Follow iTWire on Twitter

About iTWire

iTWire is all about technology news, information, jobs and community for the IT and telecommunications industry professional. Subscribe to our free ICT daily newsletter
Third 'Apple Bug' seems familiar E-mail
by Stephen Withers   
Thursday, 04 January 2007
The third instalment of the Month of Apple Bugs is less impressive than the first two, since it is apparently just a new way of exploiting a known vulnerability in QuickTime (as previously used by the MySpace XSS QuickTime worm).

The disclosure page does not indicate whether the Mac OS X version of QuickTime is affected as well as the one for Windows, and the proof of concept appears to rely on other Windows vulnerabilities. Furthermore, the exploit is described as a "cross-zone scripting attack," which is a Windows concept.

That shouldn't be taken as a claim that the QuickTime for Mac is 'safe' in this respect, but since the motivation for MoAB is said to be that "We like to play with OS X," we would have expected a Mac-based proof of concept.

Given that the QuickTime's ability to execute JavaScript contained within a movie's HREFTrack is an explicit feature (eg, to open a browser window with particular dimensions at a certain point in the movie), it isn't obvious how this issue could be best addressed within QuickTime.{moscomment}

Powered By Joomla Tags

Please enable JavaScript in your browser to post your comment!

 
< Next story in category   Previous story in the category >
iTWire user statistics Visitors last 30 days
694,279
Subscribers 15,210
#1 independent technology news advertise here
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff

- Advertisement -

Featured Whitepapers

1