Cory Cooper
Moderator
- Joined
- May 19, 2004
- Messages
- 11,113
- Reaction score
- 504
Apple released QuickTime 7.0.1 today. Enhancements/bug fixes include:
C
Available via Software Update or hereQuickTime 7.0.1
* QuickTime Quartz Composer Plugin
CVE-ID: CAN-2005-1334
Available for: QuickTime 7.0
Impact: With QuickTime 7.0, a QuickTime movie containing a maliciously crafted Quartz Composer object can leak data to an arbitrary web location.
Description: Quartz Composer objects can be wrapped in a QuickTime track and delivered as a QuickTime movie. With QuickTime 7.0, a Quartz Composer object can gather local data and send it using an encoded URL to an arbitrary web location. The QuickTime 7.0.1 update modifies the QuickTime Quartz Composer Plugin to prevent access to remote web locations. Credit to David Remahl (www.remahl.se/david) for reporting this issue.
C