1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Apple QuickTime 7.6.7 Security Update

Report ID: SA201006504
Source: F-Secure
Date of Discovery: 13.08.2010
Criticality: Undefined
Affects:
QuickTime 7 (Windows)

Compromise From: From remote
Compromise Type: Remote code execution

Summary

A security update for QuickTime 7.6.7 has been released to address a vulnerability in the Windows version of the application, which could lead to application crash or code execution. 

 

Detailed Description

Apple has released a security update for QuickTime 7.6.7 to resolve a vulnerability issue that affects the application in Windows platform.

A stack buffer overflow that exists in QuickTime's error logging could lead to application crash or arbitrary code execution. To fix this issue, the debug logging has been disabled.

NOTE: This issue does not affect Mac OS X systems.

Solution

Update to QuickTime 7.6.7 or later versions

Original Reference

About the security content of QuickTime 7.6.7 (http://support.apple.com/kb/HT4290)

CVE Reference

CVE-2010-1799