HTTP: Apple Quicktime 'HREFTrack' Cross-Zone Scripting

This signature detects attempts to exploit a known vulnerability against Apple Quicktime. Quicktime versions 7.1.3 and prior are vulnerable. iTunes versions 7.0.2.16 and prior are also vulnerable. Attackers can cause malicious scripts to be executed outside of the intended security zone by embedding them in a specially crafted MOV file.

Short Name
HTTP:STC:STREAM:QT-HREFTRACK
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
'HREFTrack' Apple Cross-Zone Quicktime Scripting
Release Date
09/28/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?