News & Information for Technology Purchasers
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Enterprise I.T. Hardware Software Communications More Topics...
Apple/Macintosh
Average Rating:
Rate this article:  
Apple Patches Critical QuickTime Bug Apple Patches Critical QuickTime Bug
By Jennifer LeClaire
May 2, 2007 10:33AM

    Bookmark and Share
In issuing the patch to fix the QuickTime vulnerability, Apple said the QuickTime bug is "very serious" and can be exploited through any Java-enabled browser with QuickTime installed, including Microsoft's Internet Explorer 7, Mozilla's Firefox, and Apple's own Safari. The QuickTime vulnerability affects Macs and Windows PCs.
 



Apple released a QuickTime update on Tuesday to block an exploit created to win a Mac-hacking contest launched last month at the CanSecWest conference in Vancouver, British Columbia.

To generate interest in the contest, 3Com's TippingPoint Relevant Products/Services division tempted technology gurus with a $10,000 prize in exchange for demonstrating how to breach a Mac through a Web browser vulnerability.

As it turns out, by enticing a user to visit a Web page containing a maliciously crafted Java applet, an attacker can exploit the QuickTime bug, leading to arbitrary code execution, according to an Apple bulletin.

The bug is considered "very serious," Apple said, and can be exploited through any Java-enabled browser, including Microsoft Relevant Products/Services's Internet Explorer 7, Mozilla's Firefox, and Apple's own Safari. The vulnerability affects Macs and Windows Relevant Products/Services PCs.

Apple's Quick Response

Michael Sutton, a security evangelist at SPI Dynamics and former director of VeriSign iDefense Labs, said he was encouraged to see Apple respond to the threat in just over one week.

"Given that the vulnerability was used at a large computer security conference, the likelihood that it would leak to others is high," Sutton noted. "The concerning issue here is that a war chest of exploits exist that have yet to be reported to vendors."

The QuickTime flaw, Sutton continued, is a situation in which a researcher hadn't yet completed work on a particular exploit, but had incentive to do so when cash and a free laptop were on the line.

"The challenge for vendors going forward is to open a line of communication with the researchers that are discovering these vulnerabilities and encourage reporting as quickly as possible," he concluded.

Gartner Condemns Hack Contest

Gartner's security experts condemned the hack-a-Mac challenge. A duo of Gartner analysts described it as a "risky endeavor" and urged sponsors to reconsider public contests along those lines in the future.

In a research note that Gartner published on Monday, analysts Rich Mogull and Greg Young said, "Public vulnerability research and 'hacking contests' are risky endeavors, and can run contrary to responsible disclosure practices, whereby vendors are given an opportunity to develop patches or remediation before any public announcements."

The pair went on to note that vulnerability research is an extremely valuable endeavor for ensuring more secure I.T. However, conducting vulnerability research in a public venue, they added, could potentially lead to mishandling or treating too lightly these vulnerabilities -- which can turn a well-intentioned action into a more ambiguous one, or inadvertently provide assistance to attackers.
 

Tell Us What You Think
Your Comment:



Advertisement


 Apple/Macintosh
1.   Macworld Focuses on Mobile Apps
2.   Analysts Expect iPad Price To Drop
3.   iPad Blitz Yields Low Buying Plans
4.   With No Killer App, iPad Is a Hard Sell
5.   iPhone Location-Based Ads Banned


advertisement
With No Killer App, iPad Is a Hard SellWith No Killer App, iPad Is a Hard Sell
The iPad still needs to prove its worth.
Average Rating:
Reporters Invited To Apple EventReporters Invited To Apple Event
New tablet could be low-end MacBook.
Average Rating:
French Exec Confirms Apple TabletFrench Exec Confirms Apple Tablet
With a webcam and 3G connectivity.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Enterprise Hardware Spotlight
Nvidia Auto-Switches Notebook GPU To Save Battery Life
Nvidia has taken the wraps off a notebook technology that chooses the best graphics processor for any given application and automatically routes the workload to Nvidia or Intel processors.
 
Microsoft Says Battery Woes Not Caused By Windows 7
Battery problems on Windows 7 machines are not caused by the operating system. That's the position of Stephen Sinofsky, head of the Windows division, in a long posting on the Windows engineering blog.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 

Enterprise Technology Spotlight
Intel Launches Quad-Core Itanium 9300 Series Processor
After two unexpected delays, Intel has launched the Itanium 9300 series, a 64-bit, quad-core processor code-named Tukwila that is expected to double the performance of its predecessor.
 
Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Hardware | Software | Communications | Network Security | Wireless Tech | Linux/Open Source
Apple/Macintosh | Microsoft/Windows | World Wide Web | Data Storage | E-Commerce | Personal Tech | Tech Trends | Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.