Short Name |
HTTP:STC:STREAM:QT-HREFTRACK |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
Apple Quicktime 'HREFTrack' Cross-Zone Scripting |
Release Date |
2010/09/28 |
Update Number |
1780 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability against Apple Quicktime. Quicktime versions 7.1.3 and prior are vulnerable. iTunes versions 7.0.2.16 and prior are also vulnerable. Attackers can cause malicious scripts to be executed outside of the intended security zone by embedding them in a specially crafted MOV file.