The winner of a recent hacking contest has uncovered
a security flaw that affects all Java-enabled browsers on all platforms,
according to a report by eWeek's Security Watch. The flaw was initially unveiled
during the
Pwn-2-Own (sic) conference, which promised a $10,000 bounty to hackers who
could break into and/or gain administrative privileges on an Apple MacBook Pro
notebook. The winner used an exploit involving QuickTime and Apple's Safari
browser, but according to Security Watch, the exploit also affects other
browsers and operating systems with QuickTime installed, including IE 6 and IE 7
on Vista. Terri Forslof, manager of security response at TippingPoint, said this
QuickTime flaw is
comparable to Microsoft's ANI vulnerability in terms of severity, and
Secunia has
rated
it highly critical-its second most serious rating (the highest being
"extremely critical.")