“The attack successfully used in last week’s CanSecWest competition exploits a Java-based flaw in QuickTime and affects all browsers on systems with the multimedia software installed, possibly including Windows, Dino Dai Zovi, who discovered the flaw, told SecurityFocus on Monday,” SecurityFocus reports.
SecurityFocus reports, “‘Firefox on Windows is considered at risk at this time,’ said Dai Zovi, who had been cleared by TippingPoint’s Zero Day Initiative to discuss certain aspects of the attack. ‘Safari and Firefox are considered vulnerable on Mac OS.'”
Full article here.
Gregg Keizer reports for Computerworld, “‘Any Java-enabled browser is a viable attack vector, if QuickTime is installed. Apple’s vulnerable code ships by default on Mac OS X (obviously) and is extremely popular on Windows, where this code introduces a third-party vulnerability,’ said Thomas Ptacek of Matasano on the group’s blog.”
Keizer reports, “Ptacek confirmed that both Safari and Mozilla Corp.’s Firefox can be exploited through the new QuickTime bug; Matasano also said it assumes that Firefox is vulnerable on Windows PCs if QuickTime’s plug-in is installed. If, as the group said, any Java-enabled browser can be exploited if QuickTime is installed, that would also place Microsoft’s Internet Explorer users in the at-risk group.”
Full article here.
[Thanks to MacDailyNews Reader “Qka” for the heads up.]
Related articles:
CanSecWest MacBook Pro challenge exploits Java-enabled browsers, including Firefox – April 23, 2007
InfoWorld publishes false report on Apple Mac security – April 21, 2007
CanSecWest’s $10,000 ‘Hack a Mac’ challenge relaxes barriers, finds exploitable hole in Safari – April 20, 2007
Apple MacBooks hold strong, remain unhacked after first day of $10,000 ‘Hack a Mac’ challenge – April 20, 2007
CanSecWest sweetens ‘Hack a Mac’ contest pot to $10,000 – April 20, 2007
CanSecWest to hold ‘PWN to OWN’ contest: pits Apple MacBook Pros vs. hackers – March 26, 2007
Microsoft’s oft-delayed, much-pared-down Windows Vista hacked at Black Hat – August 07, 2006
Microsoft publicity stunt asks hackers to attack Windows Vista – August 04, 2006
Apple Mac remains ‘unhacked’ as University of Wisconsin’s Mac OS X Security Challenge ends – March 08, 2006
Mac OS X ‘unhacked’ over 24 hours and counting in genuine security challenge – March 07, 2006