17 Gifts at All-Time Lows Gifts Under $30 ChatGPT, a Mindblowing AI Chatbot Neuralink Investigation Kirstie Alley Dies New Deadline for Real ID RSV Facts Space Tomatoes
Want CNET to notify you of price drops and the latest stories?
No, thank you
Accept

Apple updates QuickTime security

Update includes both Mac and Windows versions.

On Wednesday, Apple released QuickTime 7.4.1. The update is for users of Mac OS X v10.3.9, Mac OS X v10.4.7, Mac OS X v10.5 or later, and Windows Vista and Windows XP SP2. It addresses the vulnerability described in CVE-2008-0234.

By enticing a user to visit a maliciously crafted Web page, Apple says that an attacker may use an unpatched version of QuickTime to cause an unexpected application termination or arbitrary code execution. The vulnerability is a heap buffer overflow that exists in QuickTime's handling of HTTP responses when RTSP tunneling is enabled. Apple did not credit a researcher for reporting this vulnerability.