Alert GCSA-07070 - Vulnerabilita' multiple in Apple QuickTime
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
******************************************************************
Alert ID : GCSA-07070
Data : 12 luglio 2007
Titolo : Vulnerabilita' multiple in Apple QuickTime
******************************************************************
:: Descrizione del problema
Sono state identificate e risolte otto vulnerabilita' in Apple
QuickTime, che potrebbero essere sfruttate da un attaccante remoto
per compromettere un sistema che ne sia affetto.
Per una descrizione completa delle vulnerabilita' fare riferimento
alla segnalazione ufficiale di Apple al seguente link:
http://docs.info.apple.com/article.html?artnum=305947
:: Software e piattaforme interessate
Apple QuickTime versioni precedenti alla 7.2
:: Impatto
Esecuzione di codice arbitrario
Information exposure
Denial of Service
:: Soluzione
Aggiornare il software alla versione 7.2
per Mac:
http://www.apple.com/support/downloads/quicktime72formac.html
per Windows:
http://www.apple.com/support/downloads/quicktime72forwindows.html
:: Riferimenti
Apple
http://docs.info.apple.com/article.html?artnum=305947
Secunia
http://secunia.com/advisories/26034/
Mitre's CVE ID:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2295
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2296
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2392
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2393
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2394
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2396
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2397
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2402
-----BEGIN PGP SIGNATURE-----
iQCVAwUBRpYYevOB+SpikaiRAQJ4/AQAjLJMYy4GYPTsw2jt9OLEgCj8SrQJur5Q
UYvOR+PyKlby1HVQbsJcEIPDCdBcALKxsQhopz3Z9WCqRj8zU1kT7DikK0AZUmrp
+SOJ9eJc7DvogXS1SlLKOO5TXKA6BCb3GW2tR/XUgPeTLhCgDEQmHBsX/b04k755
lIDnbqsatVA=
=H0gQ
-----END PGP SIGNATURE-----