Apple
Apple has fixed the QuickTime vulnerability uncovered at the CanSecWest hacking conference

Apple patches QuickTime flaw

Infamous CanSecWest vulnerability fixed

Written by Shaun Nichols in California

Apple has issued a security patch for its QuickTime application nearly 11 days after the disclosure of a highly-publicised vulnerability.  

The vulnerability occurs in the way QuickTime handles JavaScript code. An attacker could use a specially-crafted Java applet embedded in a web page to execute code on a machine with the permissions of the current user.

The vulnerability was discovered by independent security researcher Dino Dai Zovi, who developed a working exploit in a matter of hours.  

Dai Zovi and partner Shane Macauley used the exploit to win a MacBook Pro and $10,000 prize at the CanSecWest security conference. 

The vulnerability was originally reported to exist only in Safari. However, Dai Zovi and Tipping Point later disclosed that the vulnerability affected all Mac and PC Java-enabled browsers on systems with QuickTime installed. 

Apple has also issued an update that fixes flaws in the AirPort and FTP components for Mac OS 10.3.9 and 10.4.9.

Tags:

Further reading

Hacking contest yields QuickTime exploit

Researcher wins $10,000 bounty with JavaScript attack   More...

QuickTime vulnerability expands to IE

Researchers execute attack in Microsoft browser   More...

Apple issues MacBook battery fix

Update addresses laptop performance issues   More...

Apple patches 802.11n Airports

Security fix covers two holes in base station's software   More...

Related articles

Mega Apple patch fixes iPhone, Safari, OS X bugs

Update repairs 54 vulnerabilities   More...

MacBook Air hacked in two minutes

Apple falls first in laptop hacking contest   More...

Apple releases seven QuickTime fixes

Vulnerabilities affect OS X and Windows versions   More...

Apple fixes critical QuickTime flaws

XP, Vista and Mac OS X versions affected   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

21 Jul 2008

3.12 MBGlobal internet reach, online spending and the space race More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Security

Major DNS flaw revealed

Experts sound alarms over early disclosure   More...

Nintendo DS

Dodgy Chinese Nintendo chargers recalled

Experience could shock some users   More...

Advertisement

Houses of Parliament

Official 'spying' requests top 500,000

Information includes web records and itemised phone bills   More...

Hacking

Small firms naïve about security

SMBs remain prone to attack, says study   More...

Advertisement