QuickTime hole waiting to be filled in
Kieren McCarthy (Techworld.com) 07/03/2004 07:40:25

A critical hole in Apple Computer's QuickTime media player has been identified and is waiting on a patch from the vendor.

The vulnerability rated at "high severity" by eEye Digital Security -- the company that discovered it -- enables malicious code to be run on someone's machine "with little user interaction". The hole exists across all versions of QuickTime and is present in the software's default settings, increasing the risk of the hole being used by hackers.

Apple was informed on Feb. 18 and is working on a patch. EEye has stuck the problem in its upcoming advisories, complete with a bar chart showing that with only fifteen days having passed since the bug was discovered, Apple users have not yet passed into dangerous territory.

The same cannot be said for Microsoft however. EEye has flagged up no less than three high severity problems with Microsoft software all of which are well past the maximum 60-day level that eEye feels is appropriate. It was eEye you'll remember that discovered the critical ASN flaw in Windows last month.

Recommend this article?
Yes0 votes
No0 votes

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Enter the fully qualified URL, eg. http://www.example.com/
Users posting comments agree to the PC World comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Syndicate content
 
Gift Guide
MWave
Samsung

CXO Latest

LED Advisor
 

Colour your world with Samsung

A chance to win with every
Samsung Consumable purchase*