About the security content of QuickTime 7.4.5

News, Security Comments Off
News Security

About the security content of QuickTime 7.4.5
Description: An issue in QuickTime’s parsing of ‘crgn’ atoms may result in a heap buffer overflow. Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue through improved bounds checking. Credit to Sanbin Li working with TippingPoint’s Zero Day Initiative for reporting this issue.

The are at least 3 other entries in the list credited to Tipping Point’s Zero Day Initiative (ZDI). I think this is win-win. People get prizes, and Apple gets high priority bugs put in front of them. Good work by all who were involved.

WP Theme & Icons by N.Design Studio
Entries RSS Comments RSS Log in