By Gregg Keizer ,
The QuickTime flaw that led to phishing attacks on MySpace can be found in both the Windows and Mac OS X versions of the media player, a security company warned Monday. Apple has yet to patch the player.
More than a week ago, MySpace shut down hundreds of user profiles that had been infected by a worm that took victims to a phishing site. The worm, dubbed "Quickspace," exploited a bug in QuickTime JavaScript support.
Finnish security company F-Secure has confirmed that the bug is in the current Windows and Mac editions of Apple Computer's QuickTime. "Any malicious JavaScript code exploiting it would affect the users of both operating systems," said S.G. Masood, F-Secure's phishing analyst, on the security vendor's blog. The Quickspace worm was originally pegged as affecting only Windows users running Microsoft's Internet Explorer browser.
Masood also pointed out that an earlier QuickTime vulnerability remains unpatched; that bug, he said, could be exploited in the same way as the one used by the Quickspace worm.
"With no fix available, the only feasible workaround for these social networking sites, and also other Web sites, is to completely block users from uploading Apple QuickTime content," Masood recommended. "This is not a MySpace only issue. [It] affects every other Web site that allows the embedding of QuickTime content."
Apple has provided a fix for the Quickspace problem to MySpace, which has distributed the patch to its users running IE. However, the computer maker has been mum on a general QuickTime update. Apple did not immediately reply to a request for comment.
University of San Diego seeking System Administrator 2 in San Diego, CA
Hebrew Senior Life seeking Network Analyst in Boston, MA
Cirrus Design seeking Web Architect in Duluth, MN
Comcast seeking Tier 4 CRAN Network Engineer in Chelmsford, MA
Lowe's seeking Network Engineer II in Mooresville, NC
For more great jobs, career-related news, features and services, please visit our Career Center.
TechWeb's FREE e-mail newsletters deliver the news you need to come out on top.
Get definitions for more than 20,000 IT terms.
Editorial and vendor perspectives