	{"id":880,"date":"2009-06-02T09:31:18","date_gmt":"2009-06-02T08:31:18","guid":{"rendered":"http:\/\/blog.intego.com\/?p=880"},"modified":"2009-06-02T09:31:18","modified_gmt":"2009-06-02T08:31:18","slug":"apple-updates-itunes-and-quicktime-security-fixes-included","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/","title":{"rendered":"Apple Updates iTunes and QuickTime: Security Fixes Included"},"content":{"rendered":"<p><img src=\"https:\/\/www.intego.com\/mac-security-blog\/images\/qticon.jpg\"><\/p>\n<p>Apple has released updates for both iTunes and QuickTime, which contain a number of security fixes. The QuickTime 7.6.2 update (<a href=\"http:\/\/support.apple.com\/kb\/HT3591\">information here<\/a>) includes fixes for maliciously crafted movie, FLC, PSD and PICT files, among others, which could lead to &#8220;unexpected application termination or arbitrary code execution.&#8221; This is a 57 MB update for Mac OS X 10.5, and a 48 MB update for 10.4.<\/p>\n<p>Macworld <a href=\"http:\/\/www.macworld.com\/article\/140919\/2009\/06\/securitypatches_itunes_quicktime.html\">is reporting<\/a> that instructions for finding one of the QuickTime flaws was &#8220;hidden&#8221; in a recent book on hacking Mac OS X written by Charlie Miller and Dino Dai Zovi. &#8220;Miller disclosed during a talk at the CanSecWest conference in March that he had hidden instructions for finding the flaw in his book. After members of Apple\u2019s security team approached him at the conference to ask about the issue, he handed over the exploit code.&#8221; <\/p>\n<p>The iTunes update (<a href=\"http:\/\/support.apple.com\/kb\/HT3592\">information here<\/a>) fixes a single vulnerability which only affects Mac OS X 10.4 and Windows: &#8220;A stack buffer overflow exists in iTunes when parsing &#8220;itms:&#8221; URLs. Accessing a maliciously crafted &#8220;itms:&#8221; URL may lead to an unexpected application termination or arbitrary code execution.&#8221; It also contains bug fixes and compatibility for the forthcoming version of the iPhone OS. It is a 72 MB update.<\/p>\n<p>Users are advised to apply these updates as soon as possible. Many users don&#8217;t realize that QuickTime is used by Mac OS X for all video and image viewing, and is therefore a very commonly used component.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Apple has released updates for both iTunes and QuickTime, which contain a number of security fixes. The QuickTime 7.6.2 update (information here) includes fixes for maliciously crafted movie, FLC, PSD and PICT files, among others, which could lead to &#8220;unexpected application termination or arbitrary code execution.&#8221; This is a 57 MB update for Mac OS [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[7,13],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"Apple has released updates for both iTunes and QuickTime, which contain a number of security fixes. The QuickTime 7.6.2 update (information here) includes\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Apple Updates iTunes and QuickTime: Security Fixes Included  - The Mac Security Blog\" \/>\n<meta property=\"og:description\" content=\"Apple has released updates for both iTunes and QuickTime, which contain a number of security fixes. The QuickTime 7.6.2 update (information here) includes\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/\" \/>\n<meta property=\"og:site_name\" content=\"The Mac Security Blog\" \/>\n<meta property=\"article:published_time\" content=\"2009-06-02T08:31:18+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intego.com\/mac-security-blog\/images\/qticon.jpg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Peter James\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\",\"name\":\"Intego\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"width\":875,\"height\":875,\"caption\":\"Intego\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/images\/qticon.jpg\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/images\/qticon.jpg\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/#webpage\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/\",\"name\":\"Apple Updates iTunes and QuickTime: Security Fixes Included - The Mac Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/#primaryimage\"},\"datePublished\":\"2009-06-02T08:31:18+00:00\",\"dateModified\":\"2009-06-02T08:31:18+00:00\",\"description\":\"Apple has released updates for both iTunes and QuickTime, which contain a number of security fixes. The QuickTime 7.6.2 update (information here) includes\",\"breadcrumb\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.intego.com\/mac-security-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Apple Updates iTunes and QuickTime: Security Fixes Included\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116\"},\"headline\":\"Apple Updates iTunes and QuickTime: Security Fixes Included\",\"datePublished\":\"2009-06-02T08:31:18+00:00\",\"dateModified\":\"2009-06-02T08:31:18+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/#webpage\"},\"wordCount\":246,\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/images\/qticon.jpg\",\"articleSection\":[\"Apple\",\"Security &amp; Privacy\"],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116\",\"name\":\"Peter James\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g\",\"caption\":\"Peter James\"},\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/author\/peter\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"Apple has released updates for both iTunes and QuickTime, which contain a number of security fixes. The QuickTime 7.6.2 update (information here) includes","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/","og_locale":"en_US","og_type":"article","og_title":"Apple Updates iTunes and QuickTime: Security Fixes Included  - The Mac Security Blog","og_description":"Apple has released updates for both iTunes and QuickTime, which contain a number of security fixes. The QuickTime 7.6.2 update (information here) includes","og_url":"https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/","og_site_name":"The Mac Security Blog","article_published_time":"2009-06-02T08:31:18+00:00","og_image":[{"url":"https:\/\/www.intego.com\/mac-security-blog\/images\/qticon.jpg"}],"twitter_card":"summary_large_image","twitter_misc":{"Written by":"Peter James","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"Intego","url":"https:\/\/www.intego.com\/mac-security-blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","width":875,"height":875,"caption":"Intego"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/#primaryimage","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/images\/qticon.jpg","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/images\/qticon.jpg"},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/","name":"Apple Updates iTunes and QuickTime: Security Fixes Included - The Mac Security Blog","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/#primaryimage"},"datePublished":"2009-06-02T08:31:18+00:00","dateModified":"2009-06-02T08:31:18+00:00","description":"Apple has released updates for both iTunes and QuickTime, which contain a number of security fixes. The QuickTime 7.6.2 update (information here) includes","breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog\/"},{"@type":"ListItem","position":2,"name":"Apple Updates iTunes and QuickTime: Security Fixes Included"}]},{"@type":"Article","@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/#article","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/#webpage"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116"},"headline":"Apple Updates iTunes and QuickTime: Security Fixes Included","datePublished":"2009-06-02T08:31:18+00:00","dateModified":"2009-06-02T08:31:18+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/#webpage"},"wordCount":246,"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-updates-itunes-and-quicktime-security-fixes-included\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intego.com\/mac-security-blog\/images\/qticon.jpg","articleSection":["Apple","Security &amp; Privacy"],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116","name":"Peter James","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g","caption":"Peter James"},"url":"https:\/\/www.intego.com\/mac-security-blog\/author\/peter\/"}]}},"jetpack_featured_media_url":"","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4VAYd-ec","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/880"}],"collection":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=880"}],"version-history":[{"count":0,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/880\/revisions"}],"wp:attachment":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=880"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=880"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=880"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}