{"id":17463,"date":"2016-04-18T09:00:50","date_gmt":"2016-04-18T01:00:50","guid":{"rendered":"https:\/\/blog.trendmicro.com.tw\/?p=17463"},"modified":"2016-04-18T15:08:58","modified_gmt":"2016-04-18T07:08:58","slug":"%e7%b7%8a%e6%80%a5%e5%91%bc%e7%b1%b2%ef%bc%9a%e5%8d%b3%e5%88%bb%e8%a7%a3%e9%99%a4%e5%ae%89%e8%a3%9d-quicktime-for-windows-%e8%bb%9f%e9%ab%94","status":"publish","type":"post","link":"https:\/\/blog.trendmicro.com.tw\/?p=17463","title":{"rendered":"\u7dca\u6025\u547c\u7c72\uff1a\u5373\u523b\u89e3\u9664\u5b89\u88dd QuickTime for Windows \u8edf\u9ad4"},"content":{"rendered":"<h1><\/h1>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" src=\"https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2015\/11\/489773775.jpg\" alt=\"\" width=\"3866\" height=\"2578\" \/><\/p>\n<p>\u5c31\u5728\u8da8\u52e2\u79d1\u6280 Zero Day Initiative \u96f6\u6642\u5dee\u6f0f\u6d1e\u61f8\u8cde\u6a5f\u69cb\u767c\u73fe\u4e86\u5169\u500b\u65b0\u7684 QuickTime for Windows \u6f0f\u6d1e\u4e0d\u4e45\u4e4b\u5f8c\uff0cApple \u5373\u5ba3\u5e03\u5373\u5c07\u7d42\u6b62\u5c0d\u8a72\u8edf\u9ad4\u7684\u652f\u63f4\u3002<\/p>\n<p>\u9019\u5169\u500b\u6f0f\u6d1e\u53ef\u80fd\u8b93\u99ed\u5ba2\u5f9e\u9060\u7aef\u57f7\u884c\u7a0b\u5f0f\u78bc\uff0c\u9032\u800c\u638c\u63a7\u53d7\u5bb3\u7684\u96fb\u8166\u3002\u82e5\u767c\u751f\u5728\u4f01\u696d\u74b0\u5883\u5167\u90e8\uff0c\u9019\u7b49\u65bc\u662f\u655e\u958b\u5927\u9580\u8b93\u99ed\u5ba2\u9032\u5165\u5168\u516c\u53f8\u7db2\u8def\u3002<\/p>\n<p>\u6839\u64da<a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=2651&amp;name=20110916\">\u8da8\u52e2\u79d1\u6280<\/a>\u5168\u7403\u5a01\u8105\u901a\u8a0a\u7d93\u7406 Christopher Budd \u8868\u793a\uff0c\u76ee\u524d\u5c1a\u672a\u770b\u5230\u6709\u4efb\u4f55\u653b\u64ca\u5df2\u5229\u7528\u9019\u4e9b\u6f0f\u6d1e\uff0c\u4f46\u554f\u984c\u662f\uff0c\u9019\u5169\u500b\u6f0f\u6d1e\u6c38\u9060\u4e5f\u6c92\u6709\u6a5f\u6703\u4fee\u88dc\u3002<\/p>\n<p>Budd \u8868\u793a\uff1a\u300c\u7e7c Microsoft Windows XP \u548c Oracle Java 6 \u4e4b\u5f8c\uff0cQuickTime for Windows \u8edf\u9ad4\u73fe\u5728\u4e5f\u52a0\u4e86\u652f\u63f4\u7d42\u6b62\u7684\u884c\u5217\uff0c\u56e0\u6b64\u672a\u4f86\u4e0d\u6703\u518d\u91cb\u51fa\u66f4\u65b0\u4f86\u4fee\u88dc\u6f0f\u6d1e\u3002\u6240\u4ee5\uff0c\u5176\u8cc7\u5b89\u98a8\u96aa\u5c07\u96a8\u8457\u88ab\u767c\u73fe\u7684\u6f0f\u6d1e\u6578\u91cf\u800c\u4e0d\u65b7\u5347\u9ad8\u3002\u6700\u7d42\u8fa6\u6cd5\u9084\u662f\u53ea\u6709\u4f9d\u7167 Apple \u5efa\u8b70\u5c07 QuickTime for Windows <a href=\"https:\/\/support.apple.com\/HT205771\">\u89e3\u9664\u5b89\u88dd<\/a>\u4e00\u9014\u3002\u300d<\/p>\n<p>\u547c\u7c72\u5927\u5bb6\u6700\u597d\u9075\u7167 Apple \u7684\u5efa\u8b70\u76e1\u5feb\u5c07 QuickTime for Windows \u8edf\u9ad4\u89e3\u9664\u5b89\u88dd\u3002<\/p>\n<p>\u539f\u56e0\u6709\u4e8c\uff1a<!--more--><\/p>\n<p><strong>\u7b2c\u4e00\uff0cApple \u5df2\u7d93\u6c7a\u5b9a\u5ee2\u9664 QuickTime for Microsoft Windows \u8edf\u9ad4<\/strong>\u3002\u8a72\u516c\u53f8\u5c07\u4e0d\u518d\u91dd\u5c0d\u8a72\u8edf\u9ad4\u7684 Windows \u7248\u672c\u63a8\u51fa\u5b89\u5168\u66f4\u65b0\uff0c\u56e0\u6b64\u5efa\u8b70\u4f7f\u7528\u8005\u5c07\u5b83\u522a\u9664\u3002\u8acb\u6ce8\u610f\uff0c\u9019\u9805\u5efa\u8b70\u4e26\u4e0d\u9069\u7528 Mac OSX \u7248\u672c\u7684 QuickTime\u3002<\/p>\n<p><strong>\u7b2c\u4e8c\uff0c<a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=2651&amp;name=20110916\">\u8da8\u52e2\u79d1\u6280<\/a>\u7684 Zero Day Initiative \u96f6\u6642\u5dee\u6f0f\u6d1e\u61f8\u8cde\u6a5f\u69cb\u5df2\u7d93\u767c\u73fe\u4e86\u5169\u9805\u6709\u95dc QuickTime for Windows \u8edf\u9ad4\u7684\u6700\u65b0\u91cd\u5927\u6f0f\u6d1e<\/strong>\uff0c\u4e5f\u5206\u5225\u767c\u51fa\u4e86\u5169\u9805\u5b89\u5168\u516c\u544a\uff1a<a href=\"https:\/\/zerodayinitiative.com\/advisories\/ZDI-16-241\/\">ZDI-16-241<\/a>\u53ca <a href=\"https:\/\/zerodayinitiative.com\/advisories\/ZDI-16-242\/\">ZDI-16-242<\/a>\u00a0\u3002Zero Day Initiative \u7684\u8cc7\u8a0a\u63ed\u9732\u653f\u7b56\u662f\uff0c\u6211\u5011\u6703\u5728\u5ee0\u5546\u6c92\u6709\u91cb\u51fa\u5b89\u5168\u66f4\u65b0\u4f86\u4fee\u88dc\u5df2\u63ed\u767c\u6f0f\u6d1e\u6642\u767c\u51fa\u5b89\u5168\u516c\u544a\u3002\u7531\u65bc Apple \u5df2\u4e0d\u518d\u70ba QuickTime for Windows \u63d0\u4f9b\u5b89\u5168\u66f4\u65b0\uff0c\u56e0\u6b64\u9019\u5169\u9805\u6f0f\u6d1e\u5c07\u6c38\u9060\u4e0d\u6703\u4fee\u88dc\u3002<\/p>\n<p>\u96d6\u7136\u76ee\u524d\u6211\u5011\u5c1a\u672a\u767c\u73fe\u4efb\u4f55\u5229\u7528\u9019\u5169\u9805\u6f0f\u6d1e\u7684\u653b\u64ca\u3002\u4f46\u552f\u4e00\u80fd\u78ba\u4fdd Windows \u7cfb\u7d71\u4e0d\u53d7\u6b64\u6f0f\u6d1e\u6216 Apple QuickTime \u5176\u4ed6\u6f0f\u6d1e\u5a01\u8105\u7684\u65b9\u6cd5\u53ea\u6709\u5c07\u5b83\u89e3\u9664\u5b89\u88dd\u4e00\u9014\u3002\u7e7c <a href=\"https:\/\/www.microsoft.com\/en-us\/WindowsForBusiness\/end-of-xp-support\">Microsoft Windows XP<\/a> \u548c <a href=\"https:\/\/www.oracle.com\/technetwork\/java\/eol-135779.html\">Oracle Java 6<\/a> \u4e4b\u5f8c\uff0cQuickTime for Windows \u8edf\u9ad4\u73fe\u5728\u4e5f\u52a0\u5165\u4e86\u652f\u63f4\u7d42\u6b62\u7684\u884c\u5217\uff0c\u56e0\u6b64\u672a\u4f86\u4e0d\u6703\u518d\u91cb\u51fa\u66f4\u65b0\u4f86\u4fee\u88dc\u6f0f\u6d1e\u3002\u6240\u4ee5\uff0c\u5176\u8cc7\u5b89\u98a8\u96aa\u5c07\u96a8\u8457\u88ab\u767c\u73fe\u7684\u6f0f\u6d1e\u6578\u91cf\u800c\u4e0d\u65b7\u5347\u9ad8\u3002<\/p>\n<p>\u5982\u9700\u66f4\u591a\u6709\u95dc\u5982\u4f55\u89e3\u9664\u5b89\u88dd Apple QuickTime for Windows \u8edf\u9ad4\u7684\u8cc7\u8a0a\uff0c\u8acb\u53c3\u95b1 Apple \u7db2\u7ad9\uff1a<a href=\"https:\/\/support.apple.com\/HT205771\">https:\/\/support.apple.com\/HT205771<\/a><\/p>\n<p><a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=2651&amp;name=20110916\">\u8da8\u52e2\u79d1\u6280<\/a>\u7684 TippingPoint \u5ba2\u6236\u56e0\u70ba\u6709 21918(ZDI-CAN-3401) \u548c 21919(ZDI-CAN-3402) \u5169\u9805\u904e\u6ffe\u898f\u5247\u7684\u95dc\u4fc2\uff0c\u5f9e 2015 \u5e74 11 \u6708 24 \u65e5\u8d77\u5373\u53ef\u9632\u7bc4\u9019\u5169\u9805\u6f0f\u6d1e\u3002<\/p>\n<p>\u4e0d\u904e\uff0c\u4f7f\u7528\u8005\u6700\u7d42\u9084\u662f\u61c9\u8a72\u4f9d\u7167 Apple \u7684\u5efa\u8b70\uff0c\u5c07 QuickTime for Windows \u89e3\u9664\u5b89\u88dd\u3002\u7531\u65bc Apple \u5df2\u4e0d\u518d\u70ba\u8a72\u8edf\u9ad4\u91cb\u51fa\u5b89\u5168\u66f4\u65b0\uff0c\u56e0\u6b64\uff0c\u9019\u662f\u552f\u4e00\u80fd\u78ba\u4fdd\u81ea\u5df1\u4e0d\u53d7\u8a72\u8edf\u9ad4\u73fe\u6709\u53ca\u672a\u4f86\u767c\u73fe\u4e4b\u6f0f\u6d1e\u5f71\u97ff\u7684\u65b9\u6cd5\u3002<\/p>\n<p>\u5728\u6280\u8853\u7d30\u7bc0\u65b9\u9762\uff0c\u9019\u5169\u500b\u6f0f\u6d1e\u90fd\u662f\u56e0 Heap \u8a18\u61b6\u9ad4\u640d\u6bc0\u800c\u8b93\u99ed\u5ba2\u80fd\u5920\u5f9e\u9060\u7aef\u57f7\u884c\u7a0b\u5f0f\u78bc\u3002\u5176\u4e2d\u4e00\u500b\u6f0f\u6d1e\u8b93\u99ed\u5ba2\u53ef\u5c07\u8cc7\u6599\u5beb\u5165\u7cfb\u7d71\u914d\u7f6e\u7684 Heap \u7de9\u885d\u5340\u4e4b\u5916\u3002\u53e6\u4e00\u9805\u6f0f\u6d1e\u5247\u51fa\u73fe\u5728 stco atom \u7576\u4e2d\uff0c\u99ed\u5ba2\u53ef\u5229\u7528\u4e00\u500b\u7121\u6548\u7684\u7d22\u5f15\u503c\u4f86\u5c07\u8cc7\u6599\u5beb\u5165\u7cfb\u7d71\u914d\u7f6e\u7684 Heap \u7de9\u885d\u5340\u4e4b\u5916\u3002\u5169\u9805\u6f0f\u6d1e\u5728\u653b\u64ca\u6642\u90fd\u9700\u8981\u5f15\u8a98\u4f7f\u7528\u8005\u9023\u4e0a\u67d0\u500b\u60e1\u610f\u7684\u7db2\u9801\u6216\u8005\u958b\u555f\u4e00\u500b\u60e1\u610f\u7684\u6a94\u6848\u3002\u800c\u4e14\u60e1\u610f\u7a0b\u5f0f\u78bc\u5728\u57f7\u884c\u6642\u90fd\u6703\u7e7c\u627f QuickTime \u64ad\u653e\u5668\u7684\u5b89\u5168\u6b0a\u9650\uff0c\u4e5f\u5c31\u662f\u7576\u6642\u767b\u5165\u7cfb\u7d71\u7684\u4f7f\u7528\u8005\u3002<\/p>\n<p>\u5169\u9805\u6f0f\u6d1e\u7684 CVSS 2.0 \u5371\u96aa\u7b49\u7d1a\u90fd\u662f 6.8\u3002\u5982\u9700\u9032\u4e00\u6b65\u8a73\u7d30\u8cc7\u8a0a\uff0c\u8acb\u53c3\u95b1\uff1a<\/p>\n<table  class=\" table table-hover\" >\n<tbody>\n<tr>\n<td width=\"16\"><\/td>\n<td>\n<ul>\n<li><a href=\"https:\/\/zerodayinitiative.com\/advisories\/ZDI-16-241\/\">https:\/\/zerodayinitiative.com\/advisories\/ZDI-16-241\/<\/a><\/li>\n<li><a href=\"https:\/\/zerodayinitiative.com\/advisories\/ZDI-16-242\/\">https:\/\/zerodayinitiative.com\/advisories\/ZDI-16-242\/<\/a><\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td><\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u5982\u9700\u66f4\u591a\u76f8\u95dc\u8cc7\u8a0a\uff0c\u8acb\u53c3\u95b1 US-CERT \u6240\u767c\u51fa\u7684\u5b89\u5168\u516c\u544a\uff1a\u00a0<a href=\"https:\/\/www.us-cert.gov\/ncas\/alerts\/TA16-105A\">https:\/\/www.us-cert.gov\/ncas\/alerts\/TA16-105A<\/a><\/p>\n<p>\u539f\u6587\u51fa\u8655\uff1a<a href=\"https:\/\/blog.trendmicro.com\/urgent-call-action-uninstall-quicktime-windows-today\/\">Urgent Call to Action: Uninstall QuickTime for Windows Today<\/a>\u4f5c\u8005\uff1a<a href=\"https:\/\/blog.trendmicro.com\/author\/christopher-budd\/\">Christopher Budd (\u5168\u7403\u5a01\u8105\u901a\u8a0a)<\/a><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u5c31\u5728\u8da8\u52e2\u79d1\u6280 Zero Day Initiative \u96f6\u6642\u5dee\u6f0f\u6d1e\u61f8\u8cde\u6a5f\u69cb\u767c\u73fe\u4e86\u5169\u500b\u65b0\u7684 QuickTime f [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_wpscppro_dont_share_socialmedia":false,"_wpscppro_custom_social_share_image":0,"_facebook_share_type":"","_twitter_share_type":"","_linkedin_share_type":"","_pinterest_share_type":"","_linkedin_share_type_page":"","_instagram_share_type":"","_medium_share_type":"","_threads_share_type":"","_google_business_share_type":"","_selected_social_profile":[],"_wpsp_enable_custom_social_template":false,"_wpsp_social_scheduling":{"enabled":false,"datetime":null,"platforms":[],"status":"template_only","dateOption":"today","timeOption":"now","customDays":"","customHours":"","customDate":"","customTime":"","schedulingType":"absolute"},"_wpsp_active_default_template":true},"categories":[12,1268,156],"tags":[2711,100,452,1462],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/17463"}],"collection":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=17463"}],"version-history":[{"count":0,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/17463\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=17463"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=17463"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=17463"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}