[ news_security_news ] QuickTime Issues Still Plague Websites
David Utter Staff Writer
2006-12-11
Insider Reports RSS Feed
Similar to the issue that allowed the MySpace worm to parade through the popular social networking site, another flaw in Apple's QuickTime can be exploited.
Windows and Mac users are vulnerable to a pair of security issues with QuickTime. Any website that permits the embedding of QuickTime content could provide an unimpeded avenue for malicious code.
These aren't features, they're security vulnerabilities. So said the advisory from F-Secure, which decried Apple's description of HREF Tracks as a feature.
Both issues with QuickTime could permit an attacker to inject a movie file with malicious JavaScript code. This could lead to activity from another worm like the Quickspace one that bothered MySpace users.
Or it could allow for phishing attacks on a compromised system. Those could lead to an unauthorized party gaining access to a service normally bound by a username and password login.
The QuickTime flaw is not just a MySpace issue. Any site permitting the embedding of QuickTime content could be targeted for this attack.
Even the workaround provided by Apple for IE users on MySpace does not correct the underlying QuickTime problem:
We have yet to see Apple acknowledge this as a security issue. On the contrary, it has claimed that this is a legitimate feature. A temporary, trivially evadible, fix was provided by Apple to MySpace that was, controversially, distributed only to MySpace users and only to those MySpace users who use IE. All other users of Apple QuickTime, including MySpace users who use a browser other than IE, are still vulnerable. And, since this fix was given only to MySpace users, other websites are still vulnerable to an attack by a worm similar to Quickspace.
---
Tag: QuickTime
Add to Del.icio.us | Digg | Reddit | Furl
Get all the updates -
About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.
More news_security_news Articles
Insider Reports RSS Feed
|
|