Forum Moderators: open

Message Too Old, No Replies

VERY serious Firefox/Quicktime Vulnerability

turn off quicktime immediately in Firefox

         

amznVibe

3:10 am on Sep 14, 2007 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



If you try the proof-of-concept test link on this disclosure/bug-report and get the word "vulnerable" (which all our machines did) then a website can run arbitrary code on your machines though Firefox. They don't even need you to click on anything, it can be auto-run.

[bugzilla.mozilla.org...]

There is no fix available yet and may take Mozilla a day or two at earliest.

Turn off quicktime *now*

Researches say this might be possible also though IE7 and Opera since the fault is really in how Quicktime works and not Firefox's flaw.

There are two places quicktime plugins might lurk:
\Program Files\QuickTime\Plugins\npqt*.dll
\Program Files\Firefox\Plugins\npqt*.dll

I suggest exiting any running browser and renaming any such .DLL to .OLD

[edited by: amznVibe at 3:23 am (utc) on Sep. 14, 2007]

Xapti

5:37 am on Sep 14, 2007 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I always hated quicktime. I wish Firefox got a damn better media player plugin. VLC is kinda nice, but it often doesn't load for many sites (whether it's the site's fault for not choosing proper MIME, or something else, it still happens), and my main beef is that it doesn't have any sort of progress/position control/indicator, volume control, etc.

huh, I had 4 npqtplugin.dll files, the original, plus 3 more with a 2,3, and 4 tacked on to the end. (FF v1.5.012)

Now that 1.5 is no longer supported, they won't be putting a fix out for it will they...(?)

huh, I tried the test cases, and quicktime plugin player just appeared and did nothing. Guess my browser wasn't vulnerable for some reason. (windows XP, FF 1.5.012)

[edited by: Xapti at 5:43 am (utc) on Sep. 14, 2007]

amznVibe

6:27 am on Sep 14, 2007 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I'm using 1.5 also and mine was vulnerable.

Renaming the files simply tried to launch the .mov externally instead of using the plugin.

Gibble

7:04 pm on Sep 18, 2007 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Never installed Quicktime here.

coopster

3:15 pm on Sep 19, 2007 (gmt 0)

WebmasterWorld Administrator 10+ Year Member



in how Quicktime works and not Firefox's flaw

Looks that way to me too. Fix available now ... Firefox 2.0.0.7 released [webmasterworld.com]