QuickTime vulnerability expands to IE

By

A QuickTime vulnerability unearthed last Friday also infects Microsoft's Internet Explorer browser.

QuickTime vulnerability expands to IE
The attack was originally demonstrated on a system running Apple's Safari browser. It was found to affect Firefox on both Windows and Mac OS X systems.

However, Terri Forslof, security response manager at Tipping Point, told VNU that by adjusting the target address of the exploit, the company's DV Labs was able to execute the exploit in both Internet Explorer 6 and 7. 

"This is going to affect all Java-enabled browsers," said Forslof.

Tipping Point acquired the details of the vulnerability as part of a US$10,000 hacking challenge.

The original vulnerability discovery and exploit development were credited to independent researcher Dino Dai Zovi.

The exploit was written for a hacking contest at the conference in which researchers were challenged to break in to a fully patched MacBook Pro system.

Forslof said that the vulnerability can be mitigated by disabling Java within the browser or by deleting the QTJava.jar file.

A spokesperson for Microsoft told VNU that the company has not found any specific flaws in Internet Explorer that allow for the attack. Microsoft suggests that users look to Apple for a fix.
Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:

Most Read Articles

Travel eSIMs secretly route traffic over Chinese and undisclosed networks: study

Travel eSIMs secretly route traffic over Chinese and undisclosed networks: study

Greater Western Water's billing system data issues laid bare

Greater Western Water's billing system data issues laid bare

Microsoft plans full quantum-resistant cryptography transition by 2033

Microsoft plans full quantum-resistant cryptography transition by 2033

Attackers weaponise Linux file names as malware vectors

Attackers weaponise Linux file names as malware vectors

Log In

  |  Forgot your password?