QuickTime Bug Still Exploitable, Security Researcher Says
It will be hard for Apple to fix the underlying problem, researchers said, because the HREF Track QuickTime feature that is exploited in these attacks is used by a number of legitimate applications. These would be broken if Apple simply disabled the feature, Erlin said. "They can’t simply pull it out," he said.
Apple is working on a "broader solution" to the QuickTime problem, a company spokesman said Thursday. He could not immediately comment on Raff’s proof-of-concept code.
-Robert McMillan, IDG News Service (San Francisco Bureau)
Check out our CIO News Alerts and Tech Informer pages for more updated news coverage.



