Feeds

QuickTime, not Safari, to blame for MacBook vuln

pwn-2-own update

Mobile application security vulnerability report

Updated The zero-day vulnerability that allowed a hacker to commandeer a brand new MacBook Pro late last week resides in a flaw in Apple's QuickTime media player, the exploit's author says. The revelation corrects descriptions given last Friday that the exploit targeted Safari.

Dino Dai Zovi set the record straight in a blog posting yesterday. It adds that Mac users browsing with Firefox are also vulnerable if QuickTime is installed and that QuickTime may put Java-enabled browsers on Windows machines at risk as well. Several hours after this story was first published, a new entry appeared that said unnamed sources at 3com have determined the QuickTime flaw is also exploitable on Internet Explorer versions 6 and 7.

Secunia has rated the QuickTime flaw highly critical, its second highest rating. "This can be exploited to execute arbitrary code when a user visits a malicious web site," the site warned. It recommends users disable Java as a work around until Apple releases a patch.

On Friday, Shane Macaulay, a friend of Dai Zovi's who participated in a "pwn-2-own" contest at the CanSecWest conference in Vancouver, described the flaw as residing in Safari. Dai Zovi, who wrote the exploit but didn't actually attend the conference, said on Tuesday that the vulnerability in fact lies in the way QuickTime handles Java. The exploit required a machine visit a booby-trapped website in order to work. Dai Zovi spent about nine hours writing the exploit, which allows a hacker to remotely gain full user rights to the targeted machine.

Under the contest rules, a successful exploit entitled the author to go home with the hacked machine. It also nets him a $10,000 bounty from security provider Tipping Point pending confirmation of the finding.

Dai Zovi on Tuesday declined to discuss the QuickTime in detail other than to say it allows a client-side Java error to execute arbitrary code when a Java-enabled browser visits a malicious website.

Dai Zovi's handiwork is only the latest discovery of a QuickTime vulnerability. Last month, Apple issued an update that plugged eight holes in the popular media playback software. ®

Boost IT visibility and business value

More from The Register

next story
Report: American tech firms charge Britons a thumping nationality tax
Without representation, too. Time for a Boston (Lincs) Macbook Party?
iPad? More like iFAD: We reveal why Apple fell into IBM's arms
But never fear fanbois, you're still lapping up iPhones, Macs
Apple gets patent for WRIST-PUTER: iTime for a smartwatch
It does everything a smartwatch should do ... but Apple owns it
For Lenovo US, 8-inch Windows tablets are DEAD – long live 8-inch Windows tablets
Reports it's killing off smaller slabs are greatly exaggerated
Cheer up, Nokia fans. It can start making mobes again in 18 months
The real winner of the Nokia sale is *drumroll* ... Nokia
Microsoft unsheathes cheap Android-killer: Behold, the Lumia 530
Say it with us: I'm King of the Landfill-ill-ill-ill
prev story

Whitepapers

Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Reducing security risks from open source software
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.