Apple Aims to Patch Persistent QuickTime Hole | Internet News

Apple Aims to Patch Persistent QuickTime Hole

Oct 4, 2007
2 minute read


Apple’s latest QuickTime update aims to fix a flaw that’s persisted in the software for more than a year — despite efforts by the computer maker to address it throughout that time.

The company now hopes to put that flaw to bed with its new QuickTime 7.2 update. The release repairs a command-injection issue in the QuickTime application’s handling of URLs, affecting Windows Vista and Windows XP SP2 users. According to Apple, Mac OSX users were not at risk from the flaw.


“By enticing a user to open a specially crafted QTL file, an attacker may cause an application to be launched with controlled command-line arguments, which may lead to arbitrary code execution,” Apple said in an advisory about the flaw.


The same issue apparently could have been triggered in Mozilla Firefox, when the browser calls a QuickTime file. Mozilla fixed the issue last month with the Firefox 2.0.0.7 release.


Apple’s update attempts to repair a problem that’s been on the company’s fix-it list for more than a year. The company first attempted to fix the issue in March with its QuickTime 7.1.5 update. That release sought to plug holes that made headlines in January, in connection with a month-long effort by two security researchers to detail Apple-related vulnerabilities, dubbed the Month of Apple Bugs project.


But the flaw is thought to be even older. The problem evidently dates back as far as September 2006, when security researcher Petko Petkov raised the alarm about arbitrary code execution vulnerabilities related to URL handling in QuickTime.

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.