Slashdot Mirror


Firefox Susceptible To QuickTime Security Flaw

Hugh Pickens writes "Apple's QuickTime media player software contains a previously undocumented security weakness in the way QuickTime handles the RTSP media-streaming protocol. The vulnerability is present in QuickTime versions 4.0 through 7.3 (the latest version) on both Windows and Mac systems. Symantec has tested the publicly available exploit code and found that it failed to work properly against Internet Explorer 6/7 or Safari 3 Beta but the exploit works against Firefox if users have chosen QuickTime as the default player for multimedia formats. Firefox users are more susceptible to this attack because Firefox farms off the request directly to the QuickTime Player as a separate process outside of its control, while IE loads the QuickTime Player as an internal plugin and when the overflow occurs, standard buffer-overflow protection is triggered, shutting down the affected processes before any damage can occur."

6 of 231 comments (clear)

  1. That does it for me... by skeftomai · · Score: 5, Funny

    Man, I'm using IE from now on. It's WAY more secure...

  2. Troll -1 by dgr73 · · Score: 4, Funny

    "Quicktime bug!?! Oh sweet Joseph of Arimathea!!!! Quick, inform the users.. YES BOTH OF THEM!"

  3. Re:And this is a firefox problem... by sm62704 · · Score: 4, Funny

    Glass half empty, half full type thing.

    The optimist says the glass is half full. The pessimist says the glass is half empty. The scientist says there is .3764666437 litres. The realist says "there's not enough". The doctor says "he's dead, Jim".

    --
    mcgrew's razor: Never attribute to stupidity that which can be explained by greedy self-interest
  4. Re:And this is a firefox problem... by znode · · Score: 4, Funny

    The engineer says that the glass is twice as large as it needs to be.

    Jack Bauer found out where the glass was, who drank the water, and which government they worked for.

  5. Re:And this is a firefox problem... by thomas.galvin · · Score: 4, Funny

    (and for the first time ever, IE just kind of sat off to the side and shrugged it's shoulders in disinterest that it isn't affected). As opposed to all of the times IE just kind of sat off to the side and shrugged it's shoulders in disinterest even though it was affected.
  6. Re:And this is a firefox problem... by Obsi · · Score: 1, Funny

    640 mL should be enough for anyone.