Apple has issued patches for its QuickTime and iTunes software. The patches fix critical vulnerabilities and a bug that was partially revealed in a book, The Mac Hacker’s Handbook, by Charlie Miller and Dino Dai Zovi, released in March.
In all, the updates fix 10 QuickTime vulnerabilities and one bug in iTunes. The flaws affect Windows and Mac users alike. The patches came bundled in the QuickTime 7.6.2 and iTunes 8.2 releases Apple published on Monday.
According to security researchers, most of the flaws were not yet known before Monday. Attackers would have to craft new exploits to target unpatched machines in order to cause damage, but plenty of damage could be done if an attacker were to succeed in exploiting one of the security flaws.
“If left unpatched, the security holes could be exploited by hackers who could create a booby-trapped movie or audio file, programmed to execute malicious code on computers,” said Graham Cluley, a senior security consultant at Sophos.
The Fatal Flaw
Although most of the bugs are not zero-day exploits, one bug in particular is cause for concern; a flaw in the way QuickTime reads files that are compressed using the JPEG 2000 compression standard. This is the bug Miller hinted at in his book.
As Miller and Zovi see it, as more and more vulnerabilities are found in the Mac OS X operating system, security researchers are realizing the importance of developing proof-of-concept exploits for those vulnerabilities. The duo’s book is described as the first to uncover the flaws in the Mac OS X operating system.
Miller and Zovi mean no harm. The white-hat hackers aim to make vital information known so consumers can find ways to secure their Mac OS X systems. The book examines the sorts of attacks that are prevented by Leopard’s security defenses, what attacks aren’t,…