A new version of QuickTime is available from Apple that plugs security holes in the software for both Mac and Windows users.
QuickTime 7.3.1 was published Thursday afternoon in order to plug unspecified "security issues," according to Apple's Web site. But the fixes appear to correct the Real Time Streaming Protocol issue identified in late November that could lead to unwanted visitors if you visited a Web site that contained code taking advantage of the flaw.
Four separate patches are available on Apple's site, three for the Mac OS X big cats Panther, Tiger, and Leopard, and one for Windows. You'll also likely be prompted by Apple's Software Update feature to download the fresh version.
Apple also published release notes about a new implementation of Java Friday morning for software developers running Tiger, Mac OS X 10.4, that fixes multiple vulnerabilities. The problems were corrected with Leopard, according to Apple.
We were all ready to nominate "iPhone to be target of hackers in 2008" for the Most Clueless Use of Future Tense in 2007 award, but it turns out the security folk quoted therein mean "hacker" in the pejorative sense. The Security and Engineering Response Team at Arbor Networks predicts the iPhone will become an increasingly common target for "drive-by attacks,' in which bad people embed malware in seemingly harmless Web pages. According to their report:
With the scrutiny the iPhone has received since its launch earlier this year over network lock-in, ASERT believes that hackers will be enticed by the possibility of attacking Apple users and the opportunity to ‘be the first’ to hack a new platform.
Geez, what kind of twisted mind would deliberately concoct software that could turn your Precious into a useless lump of semi-toxic whatnot?