<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>n&#039;1fo[r-matik] &#187; QuickTime</title>
	<atom:link href="http://www.n1fo.fr/tag/quicktime/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.n1fo.fr</link>
	<description>Pour les nymphos d&#039;infos en info...</description>
	<lastBuildDate>Tue, 07 Feb 2012 22:31:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Apple Safari 4.0.4</title>
		<link>http://www.n1fo.fr/2009/11/apple-safari-4-0-4/</link>
		<comments>http://www.n1fo.fr/2009/11/apple-safari-4-0-4/#comments</comments>
		<pubDate>Wed, 11 Nov 2009 22:45:52 +0000</pubDate>
		<dc:creator>1for-matik</dc:creator>
				<category><![CDATA[Logiciels]]></category>
		<category><![CDATA[7]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Leopard]]></category>
		<category><![CDATA[MacOS X]]></category>
		<category><![CDATA[QuickTime]]></category>
		<category><![CDATA[Safari]]></category>
		<category><![CDATA[Snow Leopard]]></category>
		<category><![CDATA[Tiger]]></category>
		<category><![CDATA[vista]]></category>
		<category><![CDATA[WebKit]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[xp]]></category>

		<guid isPermaLink="false">http://www.n1fo.fr/?p=390</guid>
		<description><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.n1fo.fr/2009/11/apple-safari-4-0-4/' addthis:title='Apple Safari 4.0.4 '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>Apple vient tout juste de publier une mise à jour pour son navigateur Safari. Mise à jour mineure qui corrige 6 failles de sécurité liés à ColorSync (1), libxml (1), Safari lui-même (1) et WebKit (3) et améliore les performances du navigateur. About Safari 4.0.4 This update is recommended for all Safari users and includes [...]]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.n1fo.fr/2009/11/apple-safari-4-0-4/' addthis:title='Apple Safari 4.0.4 '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div><p>Apple vient tout juste de publier une mise à jour pour son navigateur Safari. Mise à jour mineure qui corrige 6 failles de sécurité liés à ColorSync (1), libxml (1), Safari lui-même (1) et WebKit (3) et améliore les performances du navigateur.</p>
<blockquote>
<h2>About Safari 4.0.4</h2>
<p>This update is recommended for all Safari users and includes  improvements to performance, stability, and security including:</p>
<ul>
<li>Improved JavaScript performance</li>
<li>Improved Full History Search performance for users with a large  number of history items</li>
<li>Stability improvements for 3rd-party plug-ins, the search field  and Yahoo! Mail</li>
</ul>
</blockquote>
<p> <img src='http://www.n1fo.fr/wp-includes/images/smilies/dl.png' alt=':dl:' class='wp-smiley' />  <a href="http://www.apple.com/fr/safari/download/" target="_blank">Télécharger Apple Safari 4.0.4 avec ou sans QuickTime</a></p>
<p>En ce qui concerne les failles, voici les infos :<br />
<span id="more-390"></span></p>
<div>
<blockquote>
<h4>Safari 4.0.4</h4>
<ul type="circle">
<li><strong>ColorSync</strong>CVE-ID: CVE-2009-2804Available for: Windows 7, Vista, XP
<p>Impact: Viewing a maliciously crafted image with an embedded  color profile may lead to an unexpected application termination or  arbitrary code execution</p>
<p>Description: An integer overflow exists in the handling of images  with an embedded color profile, which may lead to a heap buffer  overflow. Opening a maliciously crafted image with an embedded color  profile may lead to an unexpected application termination or arbitrary  code execution. The issue is addressed by performing additional  validation of color profiles. This issue does not affect Mac OS X v10.6  systems. The issue has already been addressed in Security Update  2009-005 for Mac OS X 10.5.8 systems. Credit: Apple.</li>
</ul>
<ul type="circle">
<li><strong>libxml</strong>CVE-ID: CVE-2009-2414, CVE-2009-2416Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11,  Windows 7, Vista, XP
<p>Impact: Parsing maliciously crafted XML content may lead to an  unexpected application termination</p>
<p>Description: Multiple use-after-free issues exist in libxml2, the  most serious of which may lead to an unexpected application  termination. This update addresses the issues through improved memory  handling. The issues have already been addressed in Mac OS X 10.6.2, and  in Security Update 2009-006 for Mac OS X 10.5.8 systems.</li>
</ul>
<ul type="circle">
<li><strong>Safari</strong>CVE-ID: CVE-2009-2842Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac  OS X v10.5.8, Mac OS X Server v10.5.8, Mac OS X v10.6.1 and v10.6.2, Mac  OS X Server v10.6.1 and v10.6.2, Windows 7, Vista, XP
<p>Impact: Using shortcut menu options within a maliciously crafted  website may lead to the disclosure of local information</p>
<p>Description: An issue exists in Safari&#8217;s handling of navigations  initiated via the &laquo;&nbsp;Open Image in New Tab&nbsp;&raquo;, &laquo;&nbsp;Open Image in New Window&nbsp;&raquo;,  or &laquo;&nbsp;Open Link in New Tab&nbsp;&raquo; shortcut menu options. Using these options  within a maliciously crafted website could load a local HTML file,  leading to the disclosure of sensitive information. The issue is  addressed by disabling the listed shortcut menu options when the target  of a link is a local file.</li>
</ul>
<ul type="circle">
<li><strong>WebKit</strong>CVE-ID: CVE-2009-2816Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac  OS X v10.5.8, Mac OS X Server v10.5.8, Mac OS X v10.6.1 and v10.6.2, Mac  OS X Server v10.6.1 and v10.6.2, Windows 7, Vista, XP
<p>Impact: Visiting a maliciously crafted website may result in  unexpected actions on other websites</p>
<p>Description: An issue exists in WebKit&#8217;s implementation of  Cross-Origin Resource Sharing. Before allowing a page from one origin to  access a resource in another origin, WebKit sends a preflight request  to the latter server for access to the resource. WebKit includes custom  HTTP headers specified by the requesting page in the preflight request.  This can facilitate cross-site request forgery. This issue is addressed  by removing custom HTTP headers from preflight requests. Credit: Apple.</li>
</ul>
<ul type="circle">
<li><strong>WebKit</strong>CVE-ID: CVE-2009-3384Available for: Windows 7, Vista, XP
<p>Impact: Accessing a maliciously crafted FTP server could result  in an unexpected application termination, information disclosure, or  arbitrary code execution</p>
<p>Description: Multiple vulnerabilities exist in WebKit&#8217;s handling  of FTP directory listings. Accessing a maliciously crafted FTP server  may lead to information disclosure, unexpected application termination,  or execution of arbitrary code. This update addresses the issues through  improved parsing of FTP directory listings. These issues do not affect  Safari on Mac OS X systems. Credit to Michal Zalewski of Google Inc. for  reporting these issues.</li>
</ul>
<ul type="circle">
<li><strong>WebKit</strong>CVE-ID: CVE-2009-2841Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac  OS X v10.5.8, Mac OS X Server v10.5.8, Mac OS X v10.6.1 and v10.6.2, Mac  OS X Server v10.6.1 and v10.6.2
<p>Impact: Mail may load remote audio and video content when remote  image loading is disabled</li>
<p>Description: When WebKit encounters an HTML 5 Media Element  pointing to an external resource, it does not issue a resource load  callback to determine if the resource should be loaded. This may result  in undesired requests to remote servers. As an example, the sender of an  HTML-formatted email message could use this to determine that the  message was read. This issue is addressed by generating resource load  callbacks when WebKit encounters an HTML 5 Media Element. This issue  does not affect Safari on Windows systems.</ul>
</blockquote>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.n1fo.fr/2009/11/apple-safari-4-0-4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mozilla Firefox force la désactivation des extensions et plug-ins non sûrs</title>
		<link>http://www.n1fo.fr/2009/10/mozilla-firefox-force-desactivation-extensions-plug-ins-non-surs/</link>
		<comments>http://www.n1fo.fr/2009/10/mozilla-firefox-force-desactivation-extensions-plug-ins-non-surs/#comments</comments>
		<pubDate>Sun, 18 Oct 2009 13:22:11 +0000</pubDate>
		<dc:creator>1for-matik</dc:creator>
				<category><![CDATA[Logiciels]]></category>
		<category><![CDATA[.NET Frameworks]]></category>
		<category><![CDATA[AVG]]></category>
		<category><![CDATA[Deamon Tools]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[Mozilla]]></category>
		<category><![CDATA[QuickTime]]></category>

		<guid isPermaLink="false">http://www.n1fo.fr/?p=368</guid>
		<description><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.n1fo.fr/2009/10/mozilla-firefox-force-desactivation-extensions-plug-ins-non-surs/' addthis:title='Mozilla Firefox force la désactivation des extensions et plug-ins non sûrs '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>Depuis quelques jours vous avez sûrement remarqué qu&#8217;une toute nouvelle fenêtre a fait son apparition sur Mozilla Firefox 3.5 et supérieur (oui la 3.6 bêta sort le 21 Octobre) : Ne vous inquiétez pas, c&#8217;est normal ! Cette fenêtre vous indique les extensions et plug-ins contenant des failles de sécurité qui n&#8217;ont pas été mis à jour [...]]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.n1fo.fr/2009/10/mozilla-firefox-force-desactivation-extensions-plug-ins-non-surs/' addthis:title='Mozilla Firefox force la désactivation des extensions et plug-ins non sûrs '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div><p>Depuis quelques jours vous avez sûrement remarqué qu&#8217;une toute nouvelle fenêtre a fait son apparition sur Mozilla Firefox 3.5 et supérieur (oui la 3.6 bêta sort le 21 Octobre) :</p>
<p><img class="aligncenter" src="http://img44.imageshack.us/img44/741/fxexpludesac.png" alt="" width="557" height="396" /></p>
<p>Ne vous inquiétez pas, c&#8217;est normal ! Cette fenêtre vous indique les extensions et plug-ins contenant des failles de sécurité qui n&#8217;ont pas été mis à jour et que, naturellement, Firefox désactive pour le bien de votre ordinateur.</p>
<p>Cette initiative est née depuis la sortie du .NET Frameworks 3.5 SP1 où lors de son installation, Microsoft forçait l&#8217;installation d&#8217;un plug-in pour Firefox sans le consentement de l&#8217;utilisateur. De plus, étant enregistrée dans la base de registre, l&#8217;utilisateur ne pouvait même pas désinstaller ce fameux plug-in.</p>
<p>Mais biensûr, cette fonction ne désactive pas que le plug-in de Microsoft, une liste est disponible à <a href="https://www.mozilla.com/en-US/blocklist/" target="_blank">cette adresse</a> et recense notamment les plug-ins de Deamon Tools ou d&#8217;AVG SafeSearch ou même de QuickTime !</p>
]]></content:encoded>
			<wfw:commentRss>http://www.n1fo.fr/2009/10/mozilla-firefox-force-desactivation-extensions-plug-ins-non-surs/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

