Apple
A flaw in the Safari download system could allow malicious code to run
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Microsoft warns of Safari for Windows hole

Hackers could 'carpet bomb' the user's desktop

Iain Thomson, vnunet.com 05 Jun 2008
ADVERTISEMENT

Microsoft has warned of a security hole in Safari for Windows that could allow an attacker to execute code remotely on a targeted computer.

The vulnerability could allow a hacker to "carpet bomb" files onto a user's desktop via a flaw in the Safari download system that could allow malicious code to run.

"At the present time, Microsoft is unaware of any attacks attempting to exploit this blended threat," reads the Microsoft Security Advisory.

"On completion of this investigation, Microsoft will take the appropriate measures to protect our customers.

"This may include providing a solution through a service pack, the monthly update process or an out-of-cycle security update depending on customers' needs. "

Microsoft recommends that users avoid the browser or limit its ability to download directly to the desktop.

The flaw was found by vulnerability tester Nitesh Dhanjani and detailed in his blog.

"It is possible for a rogue website to litter the user's Desktop (Windows) or Downloads directory (~/Downloads/ in OSX)," he wrote.

"This can happen because the Safari browser cannot be configured to obtain the user's permission before it downloads a resource. Safari downloads the resource without the user's consent and places it in a default location (unless changed)."

See also:

Apple bugBetter late than never for iCal patches  30 May 2008
AppleResearchers lose patience after months of waiting  23 May 2008
ApplePoor warranty but gets the job done  06 May 2008
AppleFour flaws addressed in latest update  17 Apr 2008

All Hacking
Tags: Apple, Microsoft, Safari

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Greythorn IT
Leading Mobile Network vendore is currently seeking a Process consultant for a positions based either in the Middle east or Africa. We are looking for around 10 years experience with at least 5 years business ... more >
| Greythorn IT
Tier 1 Network solutions provider is currently seeking an experienced Telecommunications sales manager to work in their Abu Dhabi office. There is a brilliant benefits package as well as an attractive salary available for the ... more >
| Greythorn IT
Leading network solutions provider in Egypt is currently seeking and experienced Egyptian Network Operation /Supervision Engineer. There are competitive packages and attractive benefits package on offer for the right candidate. You will be responsible to ... more >
| Greythorn IT
A leading network Solutions vendor is currently seeking an Egyptian national to act as a Service Assurance manager out of their Egyptian office. Ideally we are looking for someone with Vendor based experience however other ... more >
More job opportunities