Apple pushes out updates for QuickTime, iTunes

Apple on Tuesday issued a new version of QuickTime and iTunes to correct 11 vulnerabilities.

Nine of the flaws are present in QuickTime and are deemed "highly critical" by vulnerability tracking firm Secunia.

Most of the bugs are buffer overflow or memory corruption issues -- and they can be exploited when a user is tricked into watching a malicious movie file, which leads to a system crash or arbitrary code execution, according to an Apple advisory. Four of the nine QuickTime holes impact Windows Vista and XP machines, while the others affect Mac OS X platforms.

On the iTunes side, one of the bugs relates to a misleading warning screen that says unblocking iTunes Music Sharing doesn't affect firewall security when it actually does, according to another advisory. The other flaw is an integer overflow issue whereby a local user could gain unauthorized system privileges.

Apple advises users to upgrade to QuickTime 7.5.5 and iTunes 8.0.

More in News

Privacy-bolstering "Apps Act" introduced in House

The bill would provide consumers nationwide with similar protections already enforced by a California law.

Microsoft readies permanent fix for Internet Explorer bug used in energy attacks

Microsoft is prepping a whopper of a security update that will close 33 vulnerabilities, likely including an Internet Explorer (IE) flaw that has been used in targeted website attacks against the U.S. government.

Weakness in Adobe ColdFusion allowed court hackers access to 160K SSNs

Up to 160,000 Social Security numbers and one million driver's license numbers may have been accessed by intruders.