National Cyber Alert System

Cyber Security Alert SA09-022A


Apple QuickTime Updates for Multiple Vulnerabilities

Original release date: January 22, 2009
Last revised: --
Source: US-CERT


Systems Affected

* AppleQuickTime 7.5 for Windows and Mac OS X


Overview

Apple has released QuickTime 7.6 to correct multiple
vulnerabilities affecting QuickTime for Mac OS X and Windows. These
vulnerabilities could allow an attacker to take control of your
computer.


Solution

Install the update

Use Software Update to upgrade to QuickTime 7.6.


Description

Apple QuickTime 7.6 addresses a number of vulnerabilities affecting
QuickTime. An attacker could exploit these vulnerabilities by
convincing a user to access a specially crafted media or movie
file. This file could be hosted on a web page or sent via email.

For more technical information, see US-CERT Technical Alert
TA09-022A.


References

* US-CERT Technical Cyber Security Alert TA09-022A -
<http://www.us-cert.gov/cas/techalerts/TA09-022A.html>

* Apple Support Downloads - <http://support.apple.com/downloads/>

* Mac OS X - updating your software -
<http://support.apple.com/kb/HT1338?viewlocale=en_US>

* Securing Your Web Browser -
<https://www.us-cert.gov/reading_room/securing_browser/#Internet_Explorer>

____________________________________________________________________

The most recent version of this document can be found at:

<http://www.us-cert.gov/cas/alerts/SA09-022A.html>
____________________________________________________________________

Feedback can be directed to US-CERT Technical Staff. Please send
email to <cert@cert.org> with "SA09-022A Feedback VU#703068" in
the subject.
____________________________________________________________________

For instructions on subscribing to or unsubscribing from this
mailing list, visit <http://www.us-cert.gov/cas/signup.html>.
____________________________________________________________________

Produced 2009 by US-CERT, a government organization.

Terms of use:

<http://www.us-cert.gov/legal.html>
____________________________________________________________________

Revision History

January 22, 2009: Initial release