On MovieTome: MovieTome: Holiday Movie Guide
BNET Business Network:
BNET
TechRepublic
ZDNet

September 12th, 2007

One-year-old QuickTime bug comes back to bite Firefox

Posted by Ryan Naraine @ 10:11 am

Categories: Apple, Botnets, Browsers, Data theft, Digital rights management, Exploit code, Firefox, Google, Hackers, Metasploit, Mozilla, Open source, Passwords, Patch Watch, Pen testing, Responsible disclosure, Rootkits, Spam and Phishing, Spyware and Adware, Viruses and Worms, Vulnerability research, Windows Vista, Zero-day attacks

Tags: Mozilla Firefox, Apple QuickTime, Ryan Naraine

One-year-old QuickTime bug comes back to bite FirefoxA year ago this month, security researcher Petko D. Petkov (left) released details on vulnerabilities in Apple’s QuickTime media player to show how movie and MP3 files can be backdoored to hack into Firefox.

Apple fixed one of the bugs but the second issue, which allows malicious manipulation of QuickTime Media Link (.qtl) files, remains unpatched and presents a serious danger to Firefox users.

According to Petkov, a U.K.-based penetration testing specialist, the result of this vulnerability can lead to full compromise of the browser and maybe even the underlying operating system.

In a blog entry that includes several proof-of-concept exploits, Petkov said the flaw can be used to install browser backdoors and take control of the underlying OS if the victim is running with administrative privileges.

I attempted to test some of the demo exploits (Firefox 2 on Mac OS X) and got this warning from Firefox:

One-year-old QuickTime bug comes back to bite Firefox

However, on a fully patched Windows XP SP2 machine running Firefox 2, one of the exploits launched calc.exe without warning:

Because QuickTime is installed by default alongside iTunes, Petkov warns that iTunes users are also at risk.

Apple does not respond to queries on individual security issues. So far this year, the company has shipped at least five QuickTime/iTunes security updates but Petkov’s one-year-old disclosure is still unpatched.

ALSO SEE:

Serious QuickTime bugs bite Windows Vista, Mac OS X

QuickTime bug brought down MacBook

[ UPDATE: September 13, 2007 at 8:33 AM ] Mozilla security chief Window Snyder has confirmed this is a “very serious issue” for Firefox users. “[We are] working with Apple to keep our users safe and we are also investigating ways to mitigate this more broadly in Firefox.

If Firefox is the default browser when a user plays a malicious media file handled by Quicktime, an attacker can use a vulnerability in Quicktime to compromise Firefox or the local machine. This can happen while browsing or by opening a malicious media file directly in Quicktime. So far this is only reproducible on Windows.

Firefox security response team is working on a fix but there’s no explanation as to why it took the two companies a full year to pay attention to Petkov’s warnings.

 

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 16 Talkback(s)
9.2
(Read the rest)
Posted by: balaknair Posted on: 09/20/07 You are currently: a Guest | | Terms of Use
People are still using Quicktime?  Carrion | 09/12/07
re: People are still using Quicktime?  Badgered | 09/12/07
Not for long.  itpro_z | 09/12/07
Quickime Stinks (stronger words could be used) - borderline "crapware"  socialism=nowhere | 09/13/07
Opening outside the browser...  Greenknight_z | 09/14/07
Rep and I are in heaven...  Mike Cox | 09/12/07
9.4  BanjoPaterson | 09/13/07
8.0  laura.b | 09/14/07
9.2  balaknair | 09/20/07
No expolit here  berck | 09/12/07
Only on my windows box  Suicida| | 09/12/07
Live Firefox's exploit here  qmlscycrajg | 09/13/07
Didn't work - blocked...  socialism=nowhere | 09/13/07
Didn't affect me  bugmenot2 | 09/13/07
Using Firefox 2.0.0.6...  zetacon4@... | 09/13/07
Proof of concept failed here  JDThompson | 09/14/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc