Go Back   Windows Vista Forum | Vista Babble > Windows Vista > Vista News

Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 09-15-2007, 07:59 PM
Snuffy's Avatar
Elite Members
 
Join Date: Nov 2006
Location: S.W. Kansas
Posts: 2,841
Snuffy is on a distinguished road
Send a message via MSN to Snuffy
Angry FireFox Unpatched Still ... 1 Year later


Unpatched QuickTime bug threatens Firefox
by Jose Vilches on September 14, 2007, 12:19 PM |
Security researcher Petko D. Petkov has released details on a year-old vulnerability in Apple's QuickTime media player that can cause Firefox to install backdoors and other malware on a fully patched computer.


"On its own, the QuickTime issue is less critical. […]Firefox is not vulnerable either. But when put together, they create a very dangerous combination," said Petkov.

According to Petkov, the current version of QuickTime contains a flaw in its Media Link function, which enables the program to parse up to 60 different file types with a compatible extension. However, because it fails to sanitize the XML content, malicious code can be pasted into media files and executed in JavaScript form. The exploit can reportedly bypass 'chrome' privileges in Firefox and its built-in security features. The researcher posted proof-of-concept code that shows how the exploit can be used to run privileged code on an unsuspecting user's computer.

Mozilla security chief Window Snyder has confirmed this is a “very serious issue” for Firefox users and said it is working with Apple on a fix, but until that happens users are advised to disable the QuickTime plug-in.
---------------------------------------------------------------
Oh Yes, you Fire Fox ppl want a link ... http://www.techspot.com/news/27034-u...s-firefox.html
I use neither one... Whee am I glad...

__________________
The only Stupid Question is the one you failed to Ask!
Beta Tester since Pre Win 95.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Sponsored Links
  #2  
Old 09-18-2007, 03:18 AM
Vistanoob's Avatar
Senior Member
 
Join Date: Sep 2007
Location: Winnipeg Manitoba
Posts: 376
Vistanoob is on a distinguished road
Send a message via MSN to Vistanoob

Good to know! I use Firefox, but not the quicktime plug-in. Scary news for users of both.
What browser do you use?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
  #3  
Old 09-18-2007, 07:09 PM
Snuffy's Avatar
Elite Members
 
Join Date: Nov 2006
Location: S.W. Kansas
Posts: 2,841
Snuffy is on a distinguished road
Send a message via MSN to Snuffy
Exclamation

IE 7. with Pro addon...

I'm sort of old fashion guy, if I drive a Ford, I do not take it to the Chey garage for service, even tho I do not like the Mechanic at Ford...

It to me is rather HARD to Beta test for MS and not use there products...
__________________
The only Stupid Question is the one you failed to Ask!
Beta Tester since Pre Win 95.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
  #4  
Old 09-19-2007, 02:34 AM
Vistanoob's Avatar
Senior Member
 
Join Date: Sep 2007
Location: Winnipeg Manitoba
Posts: 376
Vistanoob is on a distinguished road
Send a message via MSN to Vistanoob

Good point!
Firefox just automatically updated and patched the Quick Time hole, so that is a relief, as I had also read about it in a recent PC World mag. I would start a new thread but I'm not sure what to include.
The new version is 2.0.0.7 The article is at PCWorld.

Last edited by Vistanoob : 09-19-2007 at 03:05 AM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 06:18 PM.



Page generated in 0.41185 seconds with 12 queries

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23