iEntry 10th Anniversary RSS Archive

IT Management Begins With Security
SecurityProNews > News > Security News > QuickTime Issues Still Plague Websites
Search:
[ news_security_news ]

QuickTime Issues Still Plague Websites



David Utter
Staff Writer
2006-12-11

SecurityProNews: Insider Reports Insider Reports RSS Feed


Similar to the issue that allowed the MySpace worm to parade through the popular social networking site, another flaw in Apple's QuickTime can be exploited.

Windows and Mac users are vulnerable to a pair of security issues with QuickTime. Any website that permits the embedding of QuickTime content could provide an unimpeded avenue for malicious code.

These aren't features, they're security vulnerabilities. So said the advisory from F-Secure, which decried Apple's description of HREF Tracks as a feature.

Both issues with QuickTime could permit an attacker to inject a movie file with malicious JavaScript code. This could lead to activity from another worm like the Quickspace one that bothered MySpace users.

Or it could allow for phishing attacks on a compromised system. Those could lead to an unauthorized party gaining access to a service normally bound by a username and password login.

The QuickTime flaw is not just a MySpace issue. Any site permitting the embedding of QuickTime content could be targeted for this attack.

Even the workaround provided by Apple for IE users on MySpace does not correct the underlying QuickTime problem:

We have yet to see Apple acknowledge this as a security issue. On the contrary, it has claimed that this is a legitimate feature. A temporary, trivially evadible, fix was provided by Apple to MySpace that was, controversially, distributed only to MySpace users and only to those MySpace users who use IE. All other users of Apple QuickTime, including MySpace users who use a browser other than IE, are still vulnerable. And, since this fix was given only to MySpace users, other websites are still vulnerable to an attack by a worm similar to Quickspace.


---
Tag:

Add to Del.icio.us | Digg | Reddit | Furl

Get all the updates -





About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.

More news_security_news Articles

SecurityProNews: Insider Reports Insider Reports RSS Feed


Get Your Site Submitted for Free in the World's Largest B2B Directory!

Email Address:
* URL:
*
*Indicates Mandatory Field

Terms & Conditions

iEntry Featured Services: Jayde Member Services | Forums | Freeware | Advertise with Us

Virus Warnings

Subscribe to
SecurityProNews FREE!



[ more newsletters ]

article resources
Search Articles:
[advanced search]

WebProWorld.com
Get in-touch with industry experts and leaders
Post your site for review by expert and peers
Ask Security, IT, Development and Design questions

Free Membership: Join Now!

Visit WebProWorld.com

Titan Quest Forum
The #1 Titan Quest forum
Halo 3 Forum
The best Halo, Halo 2, Halo 3 forum
Nintendo Wii
Nintendo Wii news and views
Mac Software
The best in OS X freeware
Graphics Forum
Your source for graphic tutorials
SecurityProNews.com | Breaking eBusiness News Get Your IT Questions Answered - Click Here SecurityProNews News Feeds