Additional Details Emerge About Mac Hack

· by · News

Additional details have been posted about the Macintosh compromise discovered last week at the CanSecWest 2007 Conference. The exploit involves a Java-enabled Browser plus QuickTime and was documented at the Secunia Website on Tuesday.

Without disclosing the "how," Mr. Dino Dai Zovi who was the developer of a prize winning exploit of Mac OS X -- when connected to an external URL via Safari -- posted formal information about the exploit.

"The vulnerability is caused due to an unspecified error within the Java handling in QuickTime. This can be exploited to execute arbitrary code when a user visits a malicious web site using a Java-enabled browser e.g. Safari or Firefox," the advisory said.

The severity was rated as "Highly Critical." The advisory noted that other Browsers and platforms may also be affected.

John Martellaro

John Martellaro

John Martellaro was born at an early age and began writing about computers soon after that. He is a former U.S. Air Force officer and has worked for NASA, White Sands Missile Range, Lockheed Martin Astronautics, the Oak Ridge National Laboratory and Apple. At Apple he worked as a Senior Marketing Manager, a Federal Account Executive and a High Performance Computing manager. His interests include skiing, chess, science fiction and astronomy. You can follow John on Twitter at twitter.com/jmartellaro.

Sign Up for the Newsletter

Enter a valid email address

Join the TMO Express Daily Newsletter to get the latest Mac headlines in your e-mail every weekday.

Adding to list…

No Comments

Add your comment

Commenting is not available in this channel entry.