Apple released a fix for the QuickTime issue along with patches for seven other flaws in the Mac OS X that could lead to security bypass, exposure of sensitive information, Denial-of-Service attacks and system compromise.
According to the advisory, the QuickTime flaws were detected in the way the media player decodes BMP image types. A successful attacker could overwrite heap memory and potentially allow the execution of arbitrary code hidden in an image. Independent research firm Secunia rates the Mac OS X vulnerabilities as “highly critical.” The mega patch also plugs a hole in the operating system’s AFP Server, which can be exploited by guest users to disconnect AFP volumes by sending specially crafted SessionDestroy packets.
Source: Internet News

Articles RSS