FEATURED VIDEO

Sponsored By:


SLIDE SHOWS
Manufacturers brought the industry radical new ways to build PCs in 2008. Here are some of the coolest components we came across in 2008.
From gaming to business, retail to commercial, Wi-Fi to WiMAX, 2008 was the most cutting-edge year ever in the history of mobile computing.
From iPhones to BlackBerrys, 2008 saw the emergence of touch-screen titans, the first LG smartphone to hit the U.S. and the first device based on Google Android. Here are the 10 coolest smartphones that hit the market in 2008.
INSIDE CHANNELWEB
techcareers logo Search Jobs:


  

Post Resume|Employers

Recent Post:


Network Analyst
Hebrew Senior Life seeking Network Analyst in Dedham, MA
spacer

Microsoft Warns Of Bug In Apple's Safari


By Stefanie Hoffman, ChannelWeb
5:20 PM EDT Wed. Jun. 04, 2008
Microsoft issued a security advisory warning users that a flaw in Apple's Safari browser could give remote attackers the ability to install of malicious code on all versions of Windows XP and Windows Vista.

The issue was first reported May 15 by security researcher Nitesh Dhanjani, who disclosed three vulnerabilities in Safari, one of which allows a remote attacker to litter a user's desktop or Downloads directory with executable files in an attack known as carpet bombing. The glitch enables the Safari browser to download any resource, including malicious content, without the user's consent and places it in a default location.

A successful exploitation of the Safari vulnerability would work in conjunction with a bug in Microsoft's Internet Explorer Web browser, which security researchers reported more than a year ago. The attack would require a user to visit a malicious Web page while using Safari, which would trigger the carpet bomb attack and allow exploitation of the IE flaw. When combined, both the Safari and IE vulnerabilities allow malicious executables to be run on a victim's computer, which could allow attackers to take complete control of a user's computer.

Dhanjani also reported a third Safari flaw last week, which allows an attacker to remotely steal local files from the user's system. Apple said that it was working to resolve the issue, according to Dhanjani's blog post.

Dhanjani said in his posting that Apple has only promised to repair one of the three vulnerabilities detected last week and has not made clear whether there are any scheduled patches down the road for the Safari "carpet bomb" flaw. Apple did not immediately return correspondence from ChannelWeb.

The security advisory applies to all customers running Safari on Windows, although Microsoft said that the blended threat would not affect customers who have changed the default location where Safari downloads content to the local drive.

Safari is not the default browser of XP or Vista, but must be independently installed.

Microsoft said in its advisory that it was monitoring the issue and would take "appropriate measures" to protect customers, which could include a solution wrapped up in a service pack, as well as a monthly or out-of-cycle update. Microsoft also noted that it is currently working with researchers at Apple to address the issue.

So far, Microsoft claims that it is unaware of any current "loose in the wild" attacks that exploit the vulnerability.

Until an appropriate fix is released, Microsoft recommends that users limit their use of the Safari browser when surfing the Web .


RATE THIS ARTICLE Worse 1 2 3 4 5 Better
CHANNELWEB MARKETSPACE >> (Sponsored Links)
Channelweb : Promofinder
FEATURED PROMOTIONS
Weatherproof LCD Monitor
IP65 Weather/Waterproof/Outdoor LCD Monitor (LCD Display), Auto Power Saving, VESA Mounting, Sunlight Readable, Wide Temperat...
Partnerpedia Free Partner Portal
Partnerpedia is a free online community dedicated to helping companies expand their market reach through partnering. There’...
RELATED BLOG >>
Photo
Microsoft will only fix one Windows security error for its first Patch Tuesday of 2009.
ADVERTISEMENT




CHANNEL SERVICES >>