Published on: 08 January 2016
Multiple vulnerabilities are found in Apple QuickTime. A remote attacker could exploit the vulnerabilities by enticing a user to open a specially crafted movie file.
Depending on the vulnerability exploited, a successful attack could lead to unexpected application termination, or arbitrary code execution.
Apple QuickTime version 7.7.9 is released to address the issues. Users of affected systems should follow the recommendations provided by the product vendor and take immediate actions to mitigate the risk.
The new version of QuickTime is available at:
http://www.apple.com/quicktime/download/
https://support.apple.com/en-us/HT205638
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7085 (to CVE-2015-7092)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7117