Site Archives Apple

Apple QuickTime Vulnerabilities

Posted on January 22nd, 2009

GSA Reference Number: AD090122-01

Simply Put: Apple has released patches to address multiple vulnerabilities in its QuickTime media player product.   Unpatched QuickTime installations are vulnerable to remote exploitation if users view maliciously crafted files.  These vulnerabilities affect QuickTime version 7.X.

Apple Quicktime Zero-Day Advisory

Posted on April 29th, 2008

GSA Reference Number: AD080429-01

Simply Put: The Apple QuickTime Media Player is vulnerable to a remote code execution vulnerability. This remote code execution vulnerability is a security flaw that could allow a malicious file to run other programs and applications on the user’s machine when they watch a QuickTime movie. If a user opens a malicious QuickTime file, it could take over the user’s machine. The QuickTime file could be located on a website, in an email attachment or on a CD or hard drive. No patch is available at this time.