iTunes 8.2 in Software Update, supports iPhone 3.0; QuickTime & GarageBand also patched


The GarageBand update "addresses general compatibility issues, improves overall stability, and fixes a number of other minor issues [including] Improved purchasing experience for Artist Lessons in the GarageBand Lesson Store [&] Accessing installed Jam Packs in the loop browser." The update is required if you are purchasing lessons from the Lesson Store.
The iTunes update is one more clear sign that iPhone 3.0 is just around the corner. Be sure to stay tuned to our coverage of the Apple Worldwide Developer Conference next week for all your iPhone news!APPLE-SA-2009-06-01-1 QuickTime 7.6.2
QuickTime 7.6.2 is now available and addresses the following:
QuickTime
CVE-ID: CVE-2009-0188
Available for: Mac OS X v10.4.11, Mac OS X v10.5.7,
Windows Vista and XP SP3
Impact: Opening a maliciously crafted movie file may lead to an
unexpected application termination or arbitrary code execution
Description: A memory corruption issue exists in QuickTime's
handling of Sorenson 3 video files. This may lead to an unexpected
application termination or arbitrary code execution. This update
addresses the issue by performing additional validation of Sorenson 3
video files. Credit to Carsten Eiram of Secunia Research for
reporting this issue.
QuickTime
CVE-ID: CVE-2009-0951
Available for: Mac OS X v10.4.11, Mac OS X v10.5.7,
Windows Vista and XP SP3
Impact: Opening a maliciously crafted FLC compression file may lead
to an unexpected application termination or arbitrary code execution
Description: A heap buffer overflow exists in the handling of FLC
compression files. Opening a maliciously crafted FLC compression file
may lead to an unexpected application termination or arbitrary code
execution. This update addresses the issue through improved bounds
checking. Credit to an anonymous researcher working with
TippingPoint's Zero Day Initiative for reporting this issue.
QuickTime
CVE-ID: CVE-2009-0952
Available for: Mac OS X v10.4.11, Mac OS X v10.5.7,
Windows Vista and XP SP3
Impact: Viewing a maliciously crafted PSD image may lead to an
unexpected application termination or arbitrary code execution
Description: A buffer overflow may occur while processing a
compressed PSD image. Opening a maliciously crafted compressed PSD
file may lead to an unexpected application termination or arbitrary
code execution. This update addresses the issue through improved
bounds checking. Credit to Damian Put working with TippingPoint's
Zero Day Initiative for reporting this issue.
QuickTime
CVE-ID: CVE-2009-0010
Available for: Windows Vista and XP SP3
Impact: Opening a maliciously crafted PICT image may lead to an
unexpected application termination or arbitrary code execution
Description: An integer underflow in QuickTime's handling of PICT
images may result in a heap buffer overflow. Opening a maliciously
crafted PICT file may lead to an unexpected application termination
or arbitrary code execution. This update addresses the issue by
performing additional validation of PICT images. Credit to Sebastian
Apelt working with TippingPoint's Zero Day Initiative, and Chris Ries
of Carnegie Mellon University Computing Services for reporting this
issue.
QuickTime
CVE-ID: CVE-2009-0953
Available for: Mac OS X v10.4.11, Mac OS X v10.5.7,
Windows Vista and XP SP3
Impact: Opening a maliciously crafted PICT image may lead to an
unexpected application termination or arbitrary code execution
Description: A heap buffer overflow exists in QuickTime's handling
of PICT images. Opening a maliciously crafted PICT file may lead to
an unexpected application termination or arbitrary code execution.
This update addresses the issue by performing additional validation
of PICT images. Credit to Sebastian Apelt working with TippingPoint's
Zero Day Initiative for reporting this issue.
QuickTime
CVE-ID: CVE-2009-0954
Available for: Windows Vista and XP SP3
Impact: Opening a maliciously crafted movie file may lead to an
unexpected application termination or arbitrary code execution
Description: A heap buffer overflow exists in QuickTime's handling
of Clipping Region (CRGN) atom types in a movie file. Opening a
maliciously crafted movie file may lead to an unexpected application
termination or arbitrary code execution. This update addresses the
issue through improved bounds checking. This issue does not affect
Mac OS X systems. Credit to an anonymous researcher working with
TippingPoint's Zero Day Initiative for reporting this issue.
QuickTime
CVE-ID: CVE-2009-0185
Available for: Mac OS X v10.4.11, Mac OS X v10.5.7,
Windows Vista and XP SP3
Impact: Viewing a maliciously crafted movie file may lead to an
unexpected application termination or arbitrary code execution
Description: A heap buffer overflow exists in the handling of MS
ADPCM encoded audio data. Viewing a maliciously crafted movie file
may lead to an unexpected application termination or arbitrary code
execution. This update addresses the issue through improved bounds
checking. Credit to Alin Rad Pop of Secunia Research for reporting
this issue.
QuickTime
CVE-ID: CVE-2009-0955
Available for: Mac OS X v10.4.11, Mac OS X v10.5.7,
Windows Vista and XP SP3
Impact: Opening a maliciously crafted video file may lead to an
unexpected application termination or arbitrary code execution
Description: A sign extension issue exists in QuickTime's handling
of image description atoms. Opening a maliciously crafted Apple video
file may lead to an unexpected application termination or arbitrary
code execution. This update addresses the issue through improved
validation of description atoms. Credit to Roee Hay of IBM Rational
Application Security Research Group for reporting this issue.
QuickTime
CVE-ID: CVE-2009-0956
Available for: Mac OS X v10.4.11, Mac OS X v10.5.7,
Windows Vista and XP SP3
Impact: Viewing a movie file with a maliciously crafted user data
atom may lead to an unexpected application termination or arbitrary
code execution
Description: An uninitialized memory access issue exists in
QuickTime's handling of movie files. Viewing a movie file with a zero
user data atom size may lead to an unexpected application termination
or arbitrary code execution. This update addresses the issue by
performing additional validation of movie files, and presenting a
warning dialog to the user. Credit to Lurene Grenier of Sourcefire,
Inc. (VRT) for reporting this issue.
QuickTime
CVE-ID: CVE-2009-0957
Available for: Mac OS X v10.4.11, Mac OS X v10.5.7,
Windows Vista and XP SP3
Impact: Viewing a maliciously crafted JP2 image may lead to an
unexpected application termination or arbitrary code execution
Description: A heap buffer overflow exists in QuickTime's handling
of JP2 images. Viewing a maliciously crafted JP2 image may lead to an
unexpected application termination or arbitrary code execution. This
update addresses the issue through improved bounds checking. Credit
to Charlie Miller of Independent Security Evaluators, and Damian Put
working with TippingPoint's Zero Day Initiative for reporting this
issue.
Share
Source: http://apple.com/downloads
Categories
iTunes 8.2 just became available in Software Update. According to the update notes, "iTunes 8.2 now supports iPhone or iPod touch with the...
Add a Comment
My iTunes SW suddenly lost its ability to communicate with my iPod Nano. I tried reinstalling iTunes 8.2, but after about 90% of it loaded, I received the following message: "iPod service failed to start. Verify that you have sufficient privilegfes to start system services". I am set up as "computer administrator on my system, running MS XP. Anyone have any clues as to what is going on and what I need to do to fix this problem?
July 27 2009 at 12:41 PM Report abuse Permalink rate up rate down ReplyI updated and now can't open itunes at all on my mac mini??? it gives me an error message that I don't have access? I checked and all folders are shared folders - what gives, this really sucks.
June 12 2009 at 9:35 AM Report abuse Permalink rate up rate down ReplyI've also noticed that when I go to check for updates on my iphone now that the date doesn't change from the 9th of this month... So I'm guessing next Tuesday we'll be seeing 3.0... It's about time!
June 03 2009 at 8:07 PM Report abuse Permalink rate up rate down ReplyAnyone else having issues with this update? I updated at work on my Vista machine and my music files were deleted. Library still shows them, but the files are gone. Luckily I only had two songs on my work computer.
But it also happened on one of our Macs and it erased over 90 gigs of music.
I'm still running tiger and did the update this morning and now my iPhone 3G won't sync. it does not even see it when i plug it in.
June 02 2009 at 7:57 AM Report abuse Permalink rate up rate down ReplyFu5nygmen: I had the same issue with iTunes not recognizing my iPhone at all after this update. I solved it by using Disk Utility to Repair Permissions. After doing so, it synced normally when plugged in.
I noted on two iMacs (G4 800mhz PPC, and 20" Intel Core Duo) running Tiger (10.4.11) that some permissions related to iTunes were regarded as incorrect and needing repair by Disk Utility following the update. I think it's possible this is causing some of the issues being reported.
Why does it take so long to start up in windows? It's my default audio player but seems f**kin' sluggish and each update doesn't seem to add any immediately visible features.
June 02 2009 at 5:32 AM Report abuse Permalink rate up rate down ReplyI have serious trouble with scrolling (stuttering) when multi tab browsing after last night's patches, both in Safari and Firefox. Also some graphical glitches. Am I alone?
June 02 2009 at 5:27 AM Report abuse Permalink rate up rate down ReplyI also updated Jing and Launchbar to their latest releases respectively - will check if any of those are the culprits.
June 02 2009 at 5:31 AM Report abuse Permalink rate up rate down ReplyDon't know if it was mentioned before, but Genius finally works for TV shows and Movies. It didn't work for me in 8.1.1.
Other than that, I haven't noticed anything new that stands out.
I can't sync my iPhone.
When I connect now it says "iTunes could not connect with the iPhone because it is locked with a passcode. You must enter your passcode on the iPhone before it can be used with iTunes."
It didn't do this before.
After I enter the code it works. PITA!
Actually that was a security loophole I was wondering if they were ever going to fix.
Same here, although I remember this happening when a friend tried to charge his iPhone on my iTunes. A plist setting must have been reset or something.
Another thing, why did it have to analyse my library on start-up? I can't see any changes or any extra fields.
I've also noticed that if iTunes is hidden or in the background, plugging the iPhone in won't make it jump to the front =D yay for no more interruptions whilst I'm using a different program =D
there haven't been any decent feature additions to itunes since they invented the store.
compared to other management software, taggers etc it's lightweight. Well except with respect to the resources it hogs. wish they'd actually improve it for once.
They seriously need to overhaul the iTunes codebase.
Non-modal dialogs (which pop-up behind iTunes) are my pet peeve with the current codebase. The sluggish performance and Single-threadedness are my other two irritations.
iTunes 10 will (hopefully) be a complete rewrite using only Cocoa or .NET
Hot Apps on TUAW
Deals of the Day
more deals- Altec Lansing Octiv Duo iDock for $48 + free shipping
- Used Apple iMac 17" Core Duo 1.83GHz for $430 + $28 s&h
- Lounge Deluxe Stand for iPhone / iPod touch for $28 + $8 s&h
- Brookstone Surround-Sound Earbuds for $14 + $7 s&h
- Refurbished Skullcandy Tokidoki Smokin' Buds Mic'd Headset for $5 + $2 s&h
- Stitchway Backup Battery for iPod / iPhone for $5 + free shipping
Software Updates
more updates- EFI Firmware Update brings Lion Internet Recovery to 2010-model Macs
- OS X Lion 10.7.3 released with Safari 5.1.3, Wi-Fi bug fix
- Aperture updated to 3.2.2, addresses Photo Stream issue
- Apple updates Keynote to address Lion issues
- Google Search app gets new look on iPad
- Apple releases Apple TV Software Update 4.4.3



34 Comments