NIST Site Search
Search NIST.GOV
Custom Search
[Official NIST.GOV TIME]
Product Research

Advertise on this site
Possible Cross-Platform 0Day in Apple's Quicktime Music Player
Apple's Quicktime music player in combination with Safari has been identified as the attack vector that won last week's $10,000 prize at the CanSecWest security conference in Vancouver. But it turns out that the vulnerability not only extends to other OSX browsers but also possibly to Windows and PPC Macs as well. Updated: Possible Exploit Released. Fix released on May 1st. See below.No Longer Supported
The Quicktime bug seems to be passed to it by a Java capable web browser using the Quicktime for Java interface (QT4J). Any web browser that supports Java will become a vulnerability vector if Quicktime is installed. If Java support is disabled in the browser it can no longer be used for an attack.

Currently Safari and Firefox are confirmed vectors on the MacIntel OSX platform. Currently it is known that Windows Quicktime is vulnerable as well. What is not known is to what degree. If the attack is a buffer overflow an actual "exploiting the box" type attack may be OS specific. In other words Quicktime under Windows may simply crash or hang the computer if the same exploit code is used. Converting a buffer overflow in to a full fledged exploit takes time and is not always possible. But they did it on the OSX platform so it is entirely possible that someone can do it on the Windows platform as well. However, if the exploit simply takes advantage of a function built-in to Quicktime than the current exploit may work on both platforms.

Details are still emerging and part of the contest rules gives 3COM (parent company of TippingPoint's Zero Day Initiative) control over what information is released. This will limit malicious use of the bug until someone else figures it out, or until the information leaks out. Either way there is probably a little time available to allow TippingPoint to update their firewall product and Apple to fix the problem.

The exploit requires that the user visit a malicious web page, either by chance or by clicking on a malicious link.

Mitigation:
  • Turn off Java support in your browser
  • Uninstall Quicktime
  • If you use Firefox use the NoScript plugin to disallow Java on a site by site basis. There is some confusion on how to turn "Java" in the NoScript plugin. This screen shot should help. Please keep in mind that Java and JavaScript are not the same thing. This problem involves "Java". If you use Firefox you can download the latest version of NoScript at NoScript.net
  • Apple Released a Fix to this on May 1st, QuickTime version 7.1.6


Discovery credit goes to Dino Di Zovie. "Think of it as a problem that can be triggered only if Java is enabled." said Thomas Ptacek on the group's Matasano blog.

More information as it becomes available.

UPDATES:
  • 4/25 PM: Matasano Security's Thomas Ptacek is quoting "multiple credible sources" that the entire contest took place over an unsecure wireless network. Why is that important? Because in a room full of hackers some of them were surely sniffing (monitoring) the whole thing. There are unconfirmed reports that someone in that room has recreated the exploit and is releasing it in to the wild. The contest organizers are disputing this saying that the wireless access point was only used to route traffic out to the internet and that the Macbooks involved were on a wired connection. But that doesn't mean that an exploit wasn't reverse engineered by other means. So if you haven't taken measures to protect your computers yet now is the time.
  • 4/25 PM: Secunia has released Secunia Advisory #SA25011 rated as "Highly Critical". The advisory states that the vulnerability affects Apple Quicktime versions 3.x through 7.x



Share or Bookmark this Article Using:
| furl | reddit | del.icio.us | magnoliacom | digg | newsvine | stumble it |



Google
WebNIST.org
NIST.govSecurityFocus.com






Posted by NIST.org on Wednesday 25 April 2007 - 16:11:18 | |printer friendly
Translate to: French German Italian Spanish Portuguese GTM_LAN_DUTCH Russian Chinese Arabic Korean English
Google Ads




Headlines

»NIST Forensic Science Standards Committees to Hold First Public Meetings in February 2015
»NIST Security Guide Walks Organizations Through the Mobile App Security Vetting Process
»Open-Source Software for Quantum Information
»NIST Requests Round Two Comments on its Cryptographic Standards Process
»Symposium to Focus on Future of Voting Systems
»NIST Meeting: Cybersecurity Is a Key Ingredient In the Manufacturing Mix
»Future of Voting Systems Symposium II
»Global City Teams Challenge Tech Jam
»NIST Announces Initial Members of Forensic Science Digital Evidence Subcommittee
»Cybersecurity Center Invites Feedback on Securing Medical Devices
»NIST Issues New Revision of Guide to Assessing Information Security Safeguards
»Cloud Metrics Could Provide the Goldilocks Solution to Which Cloud Vendor Is aposJust Rightapos
»Filling the Gap: NIST Document to Protect Federal Information in Nonfederal Information Systems
»Cyber Security: Your Mother Was Right, Sharing is Good, And NIST Has Some Help on How
»2014 Cybersecurity Education Meeting Emphasizes Presidential Ready to Work Initiative


Date published: not known
Details

»Apple Releases Security Updates for OS X, Safari, iOS and Apple TV
Original release date: January 27, 2015 Apple has released security updates for OS X, Safari, ...
»Linux "Ghost" Remote Code Execution Vulnerability
Original release date: January 27, 2015 | Last revised: January 28, 2015 The Linux GNU C Libr ...
»Security Advisory for Adobe Flash Player
Original release date: January 26, 2015 Adobe has released Flash Player desktop version 16.0.0.296 to address a critical vulnerability (CVE-2015-0311) in 16.0.0.287 and earlier versions for Windows and Macintosh. This vulnerability could allow an attacker to take control of the affected system.Users and administrators are encouraged to review Adobe Security Bulletin APSB15-01 and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.
»IC3 Releases Alert for a Scam Targeting Businesses
Original release date: January 24, 2015 The Internet Crime Complaint Center (IC3) has release ...
»FBI Releases "Ransomware on the Rise"
Original release date: January 23, 2015 The FBI has released an article addressing ransomware ...
»Google Releases Security Updates for Chrome
Original release date: January 23, 2015 Google has released Chrome 40.0.2214.91 for Windows, ...
»Adobe Releases Security Updates for Flash Player
Original release date: January 22, 2015 Adobe has released security updates to address a vuln ...
»Oracle Releases January 2015 Security Advisory
Original release date: January 20, 2015 Oracle has released its Critical Patch Update for Jan ...
»Ubuntu Releases Security Updates
Original release date: January 20, 2015 Ubuntu has released security updates to address multi ...
»Affordable Care Act Phishing Campaign
Original release date: January 15, 2015 US-CERT is aware of a phishing campaign purporting to ...


Date published: not known
Details

»VB2014 paper: Ubiquitous Flash, ubiquitous exploits and ubiquitous mitigation
Chun Feng and Elia Florio analyse two Flash Player vulnerabilities and an IE one where Flash provide ...
»Frequently asked questions about VB2015 conference submissions
No, it doesn't have to be about malware and no, it doesn't have to be deeply technical either! Last ...
»Linux systems affected by 'GHOST' vulnerability
Proof-of-concept email gives remote access to Exim mail server. If you administer Linux-based system ...
»VB2014 paper: Design to discover: security analytics with 3D visualization engine
Thibault Reuille and Dhia Mahjoub use DNS data to look for clusters of malicious domains. Since the ...
»Adobe to patch Flash Player zero-day next week
Patch due next week as malvertising leads to Bedep trojan downloader. As the news of a zero-day vuln ...
»Alleged Flash Player zero-day used in Angler exploit kit
Adobe 'investigating reports'. Vulnerable browser plug-ins are one of the most important infection v ...
»Research paper profiles victims of targeted attacks
Large organisations working in national security and international affairs run highest risk. Anyone ...
»Paper: Nesting doll: unwrapping Vawtrak
Raul Alvarez unwraps the many layers of an increasingly prevalent banking trojan. Banking trojans re ...
»VB2014 paper: OPSEC for security researchers
Vicente Diaz teaches researchers the basics of OPSEC. Since the close of the VB2014 conference in Se ...


Date published: not known
Details

»Analyze This?
»Google Paid Over $1.5 Million In Bug Bounties In 2014
Mobile apps developed by Google now included in its Vulnerability Reward Program.
»How The Skills Shortage Is Killing Defense in Depth
It used to be easy to sell specialized security gizmos but these days when a point product gets pitc ...
»Takeaways from International Data Privacy Day: The Internet of Things
Event looks at the future of data use and how we can - and should - protect personal privacy.
»ZeroAccess Click-Fraud Botnet Back In Action Again
After a six-month hiatus, the much-diminished P2P botnet is up to its old tricks.
»Why Iran Hacks
Iran is using its increasingly sophisticated cyber capabilities to minimize Western influence and es ...
»'Ghost' Not So Scary After All
The latest open-source Linux vulnerability is serious but some security experts say it's not that ea ...
»Small Changes Can Make A Big Difference In Tech Diversity
There's no doubt that many employers feel most comfortable hiring people like themselves. But in Inf ...
»Half Of Enterprises Worldwide Hit By DDoS Attacks, Report Says
New data illustrates how distributed denial-of-service (DDoS) attacks remain a popular attack weapon ...


Date published: Sun, 01 Feb 2015 14:13:26 EST
Details
Main Menu
· Home
Current Security News
 
SANS Internet Storm Center, InfoCON: green

» Infocon: green

» Improving SSL Warnings, (Sun, Feb 1st)
[01 Feb 2015 09:44am]

» Beware of Phishing and Spam Super Bowl Fans!, (Sat, Jan 31st)
[30 Jan 2015 09:43pm]

» ISC StormCast for Friday, January 30th 2015 http://isc.sans.edu/podcastdetail.html?id=4335, (Fri, Jan 30th)
[29 Jan 2015 09:05pm]

» Blindly confirming XXE, (Thu, Jan 29th)
[29 Jan 2015 11:43am]

» ISC StormCast for Thursday, January 29th 2015 http://isc.sans.edu/podcastdetail.html?id=4333, (Thu, Jan 29th)
[28 Jan 2015 08:34pm]

» Adobe Flash Update Available for CVE-2015-0311 & -0312, (Wed, Jan 28th)
[28 Jan 2015 01:23pm]

» GHOST glibc gethostbyname() Vulnerability: https://www.youtube.com/watch?v=218JiCBpUTM, (Wed, Jan 28th)
[28 Jan 2015 09:01am]

» ISC StormCast for Wednesday, January 28th 2015 http://isc.sans.edu/podcastdetail.html?id=4331, (Wed, Jan 28th)
[28 Jan 2015 08:43am]

» VMware Security Advisories - 1 New, 1 Updated, (Wed, Jan 28th)
[27 Jan 2015 05:48pm]

» New Critical GLibc Vulnerability CVE-2015-0235 (aka GHOST), (Tue, Jan 27th)
[27 Jan 2015 04:56pm]

***
CNET News.com

» Microsoft defends opening Hotmail account of blogger in espionage case
[20 Mar 2014 06:47pm]

» Syria's Internet goes dark for several hours
[20 Mar 2014 04:25pm]

» Symantec fires CEO Steve Bennett
[20 Mar 2014 03:07pm]

» Microsoft sniffed blogger's Hotmail account to trace leak
[20 Mar 2014 01:28pm]

» Microsoft sniffed private Hotmail account to trace trade secret leak
[20 Mar 2014 01:28pm]

» IBM's new services zero in on fraud, financial crime
[20 Mar 2014 07:31am]

» Despite assault on privacy, Page sees value in online openness
[19 Mar 2014 08:00pm]

» Hackers transform EA Web page into Apple ID phishing scheme
[19 Mar 2014 05:21pm]

» NSA top lawyer says tech giants knew about data collection
[19 Mar 2014 02:57pm]

» Microsoft touts study showing the cost of pirated software
[19 Mar 2014 06:55am]

» Microsoft touts study showing cost of malware in pirated software
[19 Mar 2014 06:55am]

» How to spy on your lover, the smartphone way
[18 Mar 2014 01:24pm]

» Mt. Gox update lets users see their Bitcoin balances
[18 Mar 2014 06:38am]

» Fake Malaysia Airlines links spread malware
[17 Mar 2014 05:12pm]

» IBM: No, we did not help NSA spy on customers
[17 Mar 2014 01:15pm]

***

***



***


More IT Security
News Feeds
More Sponsors

Advertise on this site
RSS Feeds
Our news can be syndicated by using these rss feeds.
rss1.0
rss2.0
rdf
Symantec News

NIST.org is in no way connected to the U.S. government site NIST.gov

This site is © John Herron, CISSP. All Rights Reserved.

Please visit daily to stay up to date on all your IT Security compliance issues.

http://www.nist.org -
Hosted by BlueHost. We've never had a better hosting company.
{THEMEDISCLAIMER}