Site icon MacDailyNews

Apple releases Mac OS X Security Update 2007-001

Apple today released Security Update 2007-001 (Universal) and Security Update 2007-001 (Panther) which is recommended for all users and improves QuickTime security.

CVE-ID: CVE-2007-0015: Available for: QuickTime 7.1.3 on Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.8, Mac OS X Server v10.4.8, Windows XP/2000

Impact: Visiting malicious websites may lead to arbitrary code execution

Description: A buffer overflow exists in QuickTime’s handling of RTSP URLs. By enticing a user to access a maliciously-crafted RTSP URL, an attacker can trigger the buffer overflow, which may lead to arbitrary code execution. A QTL file that triggers this issue has been published on the Month of Apple Bugs web site (MOAB-01-01-2007). This update addresses the issue by performing additional validation of RTSP URLs.

Security Update 2007-001 is available via Software Update and also as standalone installers:

Security Update 2007-001 (Universal) 4.9MB
Security Update 2007-001 (Panther) 2.4MB

More info: http://docs.info.apple.com/article.html?artnum=304989

Exit mobile version