Latest Comments
"Hi this is the mail I received Brett Karpman show details Nov 17 (3 days ago) Reply Atten..."
by Rodney Churchyard | Nov 20, 2008 6:13 PM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"Umm. no. The 6.5 product is mounting the offline VM image and performing a scan for patch ..."
by eric | Nov 20, 2008 8:15 AM
 
"it's great i tried it"
by divyacharan | Nov 20, 2008 12:24 AM
 
"I actually love the RoboForm software myself. I use it all of the time and it takes all of the ..."
by Omarra Byrd | Nov 18, 2008 8:19 AM
Web

QuickTime bug exposed at CanSecWest more than just a Safari flaw

  • Email a Friend
  • Print Page
QuickTime bug exposed at CanSecWest more than just a Safari flaw
By Frank Washkuch
Apr 26, 2007 10:26 AM
Tags: QuickTime | bug | exposed | at | CanSecWest | more | than | just | a | Safari | flaw
Macaulay won a MacBook, and his partner Dino Dai Zovi earned US$10,000, for displaying the flaw. In the process, he exposed a vulnerability in Apple’s QuickTime media player that can be exploited on any Java-enabled browser.

The flaw is caused by an unspecified error within QuickTime’s Java handling and exists on Safari, Firefox and any Java-enabled browser. It can be exploited by attackers to execute arbitrary code, according to Secunia, which ranked the flaw as "highly critical."

The advisory warned that other browsers may be affected as well, and urged end users to disable Java support and avoid untrusted websites.

Secunia also credited Dai Zovi with discovering the flaw.

Researcher Thomas Ptacek said Monday on the Matasano Chargen blog that the Safari and Firefox are confirmed vectors on MacIntel, and Firefox is a presumed vector on Windows if QuickTime is installed.

Terri Forslof, manager of security response at TippingPoint, told SCMagazine.com on Monday that the vulnerability can be exploited on any browser using Java.

She said the QuickTime flaw was not patched in Apple’s latest round of security updates, released last week.

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
 
Vulnerabilities & Exploits Whitepapers