 |
Apple on Tuesday posted a security update for its QuickTime media technology. The update fixes two issue. The first issue is with an implementation issue in QuickTime for Java, “which may allow instantiation or manipulation of objects outside the bounds of the allocated heap.” When a user goes to a Web page containing a maliciously crafted Java applet, a hacker could trigger the flaw leading to arbitrary code execution.
The second issue may lead to the disclosure of sensitive information. Again, utilizing an issue with QuickTime for Java, this flaw could allow a web browser’s memory to be read by a Java applet. This update addresses the issue by clearing memory before allowing it to be used by Java applets.
|
|
|
|