Tuesday, April 24, 2007

Mac Hacked Through QuickTime Flaw

Here's something for all of us to take note of:

Mac hacked through QuickTime flaw
Hack-a-Mac contest winner exploited a zero-day bug in QuickTime that could also expose Windows users.

By Joris Evers, Staff Writer, CNET News.com
Published: April 24, 2007, 11:39 AM PDT

The security hole used to breach a MacBook in a hack-a-Mac competition last week lies in Apple's QuickTime media player, the flaw finder said Tuesday.

The vulnerability is related to how QuickTime handles Java, said security researcher Dino Dai Zovi. An attacker can exploit the bug through Safari or Firefox, he said. Initial reports were that the flaw was in Safari, Apple's Web browser.

"It is a vulnerability within QuickTime. Safari and Firefox on Mac OS X are vulnerable," Dai Zovi said. QuickTime is also widely used on Windows machines, so Windows users may also be at risk, he said. "At this time, Firefox on Windows is considered at risk," Dai Zovi said.

http://news.com.com/Mac++hacked+through+QuickTime+flaw/2100-1002_3-6178787.html?tag=nefd.top

No comments: