Apple - QuickTime Bug Affects All Java-Enabled Browsers - eWeek Security Watch | eWeek

QuickTime Bug Affects All Java-Enabled Browsers

Écrit par
Lisa Vaas
Lisa Vaas
Apr 26, 2007
2 minute read
eWeek Le contenu et les recommandations de produits sont indépendants de la rédaction. Nous pouvons gagner de l'argent lorsque vous cliquez sur des liens vers nos partenaires. En savoir plus

The QuickTime bug revealed at CanSecWest last week turns out to affect everything that’s Java-enabled and that has QuickTime installed, including IE 6 and IE 7 on Vista, browsers that were originally thought to be safe due to sandboxing techniques. Researchers are urging all users of QuickTime–and that means you, if you have iTunes installed–to turn off Java.

That Apple’s Safari browser is an attack vector for the flaw was known on Friday, when Matasano Security principle Dino Dai Zovi used it to earn a $10,000 cash prize in the Pwn-2-Own contest at CanSecWest. Soon after, TippingPoint added Mozilla’s Firefox to the list of attack vectors, and on Tuesday night discovered that IE is also an attack vector.

Terri Forslof, manager of security response at TippingPoint, said this QuickTime flaw is comparable to Microsoft’s ANI vulnerability in terms of severity, and Secunia has rated it highly critical—its second most serious rating (the highest being “extremely critical.”)

“This is probably one of the biggest vulnerabilities we’ve seen,” Forslof told me today. “It affects every platform, every browser. It’s widespread, and nobody’s immune to this thing.”

As of now, there is no exploit code out in the wild, although one blogger calling him or herself “Infosecsellout” is making claims that he or she has “the advantage of a full packet capture of the entire contest” and has confirmed the vulnerability with “good ‘ol fashioned vulnerability research.”

These claims are being dismissed by CanSecWest organizers, who stand behind the security of the network on which the Pwn-2-Own contest was held. Forslof dismissed the blogger as an irresponsible exploiter dealing in nothing but FUD. The supposed exploit nabber’s claims are also undermined by the fact that he or she didn’t get the flaw’s technical details right, calling it a JavaScript-enabled flaw as opposed to what it is: a Java-enabled flaw. (Disclaimer: The blogger might have gotten that fallacy from me—I believe this might be the case, given that he or she referred to press reports comparing the severity of the QuickTime bug to that of the ANI vulnerability. In my feeble defense, I only said JavaScript once, and it was a typo. Plus, I’m not making foolish FUD claims and getting people at Mozilla and Microsoft all cooked up over the thought that the exploit’s in the wild. Shame, Sellout, shame.)

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Propriété de TechnologyAdvice. © 2026 TechnologyAdvice. Tous droits réservés

Divulgation publicitaire : Certains des produits qui apparaissent sur ce site proviennent d'entreprises dont TechnologyAdvice reçoit une compensation. Cette compensation peut influencer la façon dont les produits apparaissent sur ce site, notamment l'ordre dans lequel ils apparaissent. TechnologyAdvice n'inclut pas toutes les entreprises ou tous les types de produits disponibles sur le marché.