-
Website
http://www.matasano.com/log -
Original page
http://www.matasano.com/log/812/breaking-macbook-vuln-in-quicktime-affects-win32-apple-code/ -
Subscribe
All Comments -
Community
-
Top Commenters
-
Press Controls
3 comments · 2 points
-
ChrisMtso
12 comments · 1 points
-
Eric Monti
11 comments · 1 points
-
StatlerAndWaldorf
12 comments · 3 points
-
Dave G.
7 comments · 1 points
-
-
Popular Threads
That would explain why disabling Java will block the vuln, and also why it should readily affect other OSes.
Nice discovery, will certainly keep Apple awake for a few nights.
http://noscript.net
Thanks for the info!
2) Still waiting for information as to whether this vuln takes advantage of a poorly thought out built-in Quicktime function or executes after a buffer overflow. This information greatly affects how this affects Windows. This info is probably still embargoed.
So I recommend doing, uh, nothing.
Tom: on the overwhelming majority of deployed Macs, breaking Safari puts you one move away from checkmate --- "admin" users are root-equivalent.
But who cares? Read this:
http://www.matasano.com/log/809/a-little-challe...
Especially the comments.
Worrying about "root" on a single-user machine is like worrying about a bank robber stealing the doors and the chairs.
If this hasn't been reported to Apple, this notice is dubious at best. To release a notice about a vulnerability and not report it to the accountable parties is irresponsible rumor-mongering. I would hope this isn't the kind of thing matasano is participating in.
PPC forever (or at least until the warranty runs out).
Oh ye of infinite patience.
If this was a Java vulnerability, then it would be a Java bug, not a Quicktime bug. This would put Linux, *BSD, etc. at risk as well. But this is not just a drive-by download via Java (haven't heard of any drive-by downloading via Java, except if malware is already installed), it's Quicktime's handling of it.
Just for future reference people, if "Java" is said, then take it as Java, not "Javascript," they are two totally different things.
Uninstalling Quicktime seems to stop the vulnerability as well. ;)
AMD 1800 XP (like a Pent 4) and have QuickTime 6.4
The Apple site said I can't upgrade/Patch unless
I have an NT type O/S.
What are my options, Please?
Regards, Richard dickie@pobox.com
ps how to disable Java, if that's what I must do or
uninstal QuickTime? What about those 3rd party programs with Codecs packages that esentially compete with QT & Real player?? rrrr