also @ TechSpot: Sony patent aims to put content-interrupting commercials in video games

Unpatched QuickTime bug threatens Firefox

By

On September 14, 2007, 12:19 PM EST

Security researcher Petko D. Petkov has released details on a year-old vulnerability in Apple's QuickTime media player that can cause Firefox to install backdoors and other malware on a fully patched computer.

"On its own, the QuickTime issue is less critical. […]Firefox is not vulnerable either. But when put together, they create a very dangerous combination," said Petkov.
According to Petkov, the current version of QuickTime contains a flaw in its Media Link function, which enables the program to parse up to 60 different file types with a compatible extension. However, because it fails to sanitize the XML content, malicious code can be pasted into media files and executed in JavaScript form. The exploit can reportedly bypass 'chrome' privileges in Firefox and its built-in security features. The researcher posted proof-of-concept code that shows how the exploit can be used to run privileged code on an unsuspecting user's computer.

Mozilla security chief Window Snyder has confirmed this is a “very serious issue” for Firefox users and said it is working with Apple on a fix, but until that happens users are advised to disable the QuickTime plug-in.

Related Stories

No tags on this story

Post a new comment

Guest user

To post as an anonymous
user click here
.

Members

If you are a TechSpot member,
please login first.


By signing up you gain complete access to the TechSpot community. Join thousands of computer and technology enthusiasts that contribute and share knowledge in our forum. Post messages, get a private inbox, upload your own photo gallery and more.

Subscribe to TechSpot

Get free exclusive content, learn about new features and tech breaking news.