Quicktime Security Update for 7.1.6 (Yes, really!)
/** Hope you Windows guys have better luck with this update than other Apple Updates in the past **/
UPDATE: Alot of people have written in telling us that 7.1.6 is the current version and there are no other updates. Yes, 7.1.6 IS CURRENT. This is a security update FOR 7.1.6 as indicated in the subject. Please see: http://www.apple.com/support/downloads/ you will see that there ARE Security Updates.
http://docs.info.apple.com/article.html?artnum=305531
Security Update (QuickTime 7.1.6)
QuickTime
CVE-ID: CVE-2007-2388
Available for: QuickTime 7.1.6 for Mac OS X and Windows
Impact: Visiting a malicious website may lead to arbitrary code execution
Description: An implementation issue exists in QuickTime for Java, which may allow instantiation or manipulation of objects outside the bounds of the allocated heap. By enticing a user to visit a web page containing a maliciously crafted Java applet, an attacker can trigger the issue which may lead to arbitrary code execution. This update addresses the issue by performing additional validation of Java applets. Credit to John McDonald, Paul Griswold, and Tom Cross of IBM Internet Security Systems X-Force, and Dyon Balding of Secunia Research for reporting this issue.
QuickTime
CVE-ID: CVE-2007-2389
Available for: QuickTime 7.1.6 for Mac OS X and Windows
Impact: Visiting a malicious website may lead to the disclosure of sensitive information
Description: A design issue exists in QuickTime for Java, which may allow a web browser's memory to be read by a Java applet. By enticing a user to visit a web page containing a maliciously crafted Java applet, an attacker can trigger the issue which may lead to the disclosure of sensitive information. This update addresses the issue by clearing memory before allowing it to be used by untrusted Java applets.
(Information came from Apple's website)
--
Joel Esler
http://handlers.sans.org/jesler
UPDATE: Alot of people have written in telling us that 7.1.6 is the current version and there are no other updates. Yes, 7.1.6 IS CURRENT. This is a security update FOR 7.1.6 as indicated in the subject. Please see: http://www.apple.com/support/downloads/ you will see that there ARE Security Updates.
http://docs.info.apple.com/article.html?artnum=305531
Security Update (QuickTime 7.1.6)
QuickTime
CVE-ID: CVE-2007-2388
Available for: QuickTime 7.1.6 for Mac OS X and Windows
Impact: Visiting a malicious website may lead to arbitrary code execution
Description: An implementation issue exists in QuickTime for Java, which may allow instantiation or manipulation of objects outside the bounds of the allocated heap. By enticing a user to visit a web page containing a maliciously crafted Java applet, an attacker can trigger the issue which may lead to arbitrary code execution. This update addresses the issue by performing additional validation of Java applets. Credit to John McDonald, Paul Griswold, and Tom Cross of IBM Internet Security Systems X-Force, and Dyon Balding of Secunia Research for reporting this issue.
QuickTime
CVE-ID: CVE-2007-2389
Available for: QuickTime 7.1.6 for Mac OS X and Windows
Impact: Visiting a malicious website may lead to the disclosure of sensitive information
Description: A design issue exists in QuickTime for Java, which may allow a web browser's memory to be read by a Java applet. By enticing a user to visit a web page containing a maliciously crafted Java applet, an attacker can trigger the issue which may lead to the disclosure of sensitive information. This update addresses the issue by clearing memory before allowing it to be used by untrusted Java applets.
(Information came from Apple's website)
--
Joel Esler
http://handlers.sans.org/jesler
Keywords:
0 comment(s)
Global Crossing having some network issues
Eric wrote in to tell us:
"Global Crossing has a major outage in Dallas, TX which is causing more issues within their core. 500+ms latency and 10%+ dropped packets."
http://internethealthreport.com/ is showing issues with GC. GC is aware of the issue and is working to resolve it.
The Internet is not melting yet.
UPDATE: This appears to have been resolved.
--
Joel Esler
http://handlers.sans.org/jesler
"Global Crossing has a major outage in Dallas, TX which is causing more issues within their core. 500+ms latency and 10%+ dropped packets."
http://internethealthreport.com/ is showing issues with GC. GC is aware of the issue and is working to resolve it.
The Internet is not melting yet.
UPDATE: This appears to have been resolved.
--
Joel Esler
http://handlers.sans.org/jesler
Keywords:
0 comment(s)
Signature Blocks
Just thought i'd share with you all a pet peeve of mine. Signature Blocks in email.
How much is too much? At what point do these things become a security hazard? At what point are you putting too much information about yourself out on the internet?
Well wait, you ask, what does this have to do with security? What if your email client has a vuln to some client side jpg/png/gif parsing thingy, and all I have to do is send you an email with an html signature block (or html at ALL), and execute some code?
Do you put certs in your signature block? Should you?
Do you put quotes in your signature block? Should you?
Do you put your phone number in your signature block? Email addresses? Titles?
I've stuck to the rule of '4 lines is enough' in a signature block. But what are your thoughts?
Does your company have a policy against signature blocks? What about those Plaxo signature blocks? What about LinkedIn signature blocks?
Share your thoughts. I'll collect the consensus for the night and publish a diary with your thoughts.
--
Joel Esler
http://handlers.sans.org/jesler
P.S. For those of you that are wondering, my email signature block is one line.
How much is too much? At what point do these things become a security hazard? At what point are you putting too much information about yourself out on the internet?
Well wait, you ask, what does this have to do with security? What if your email client has a vuln to some client side jpg/png/gif parsing thingy, and all I have to do is send you an email with an html signature block (or html at ALL), and execute some code?
Do you put certs in your signature block? Should you?
Do you put quotes in your signature block? Should you?
Do you put your phone number in your signature block? Email addresses? Titles?
I've stuck to the rule of '4 lines is enough' in a signature block. But what are your thoughts?
Does your company have a policy against signature blocks? What about those Plaxo signature blocks? What about LinkedIn signature blocks?
Share your thoughts. I'll collect the consensus for the night and publish a diary with your thoughts.
--
Joel Esler
http://handlers.sans.org/jesler
P.S. For those of you that are wondering, my email signature block is one line.
Keywords:
0 comment(s)
Apple Security Update 2007-005
According to this page:
Apple Security Update 2007-005 updates the following components:
bind
CarbonCore
CoreGraphics
crontabs
fetchmail
file
iChat
mDNSResponder
PPP
ruby
screen
texinfo
VPN
Time for updates. This is especially critical for the mDNSResponder update!
--
Joel Esler
http://handlers.sans.org/jesler
Apple Security Update 2007-005 updates the following components:
bind
CarbonCore
CoreGraphics
crontabs
fetchmail
file
iChat
mDNSResponder
PPP
ruby
screen
texinfo
VPN
Time for updates. This is especially critical for the mDNSResponder update!
--
Joel Esler
http://handlers.sans.org/jesler
Keywords:
0 comment(s)
×
Diary Archives
Comments