FEATURED VIDEO

Sponsored By:


SLIDE SHOWS
ChannelWeb's Top 25 Execs of 2008 know that reading is fundamental. Here are their picks for books to feed your brain.
There were plenty of high-powered movers and shakers that made a big impact on the channel in 2008. Here's a look at who made our list of the 25 most influential.
It's time again to agonize over what to get the techie in your life. With the holidays closing in fast, here are 25 gift ideas sure to wow any techie.
INSIDE CHANNELWEB
techcareers logo Search Jobs:


  

Post Resume|Employers

Recent Post:


Regional Desktop Coordinator
BP seeking Regional Desktop Coordinator in Houston, TX
spacer

Apple Releases Fix For Safari 'Carpet Bomb' Error


By Stefanie Hoffman, ChannelWeb
5:18 PM EDT Fri. Jun. 20, 2008
Apple released Safari patch 3.1.2 Thursday, fixing critical errors, including a so-called carpet bomb bug, that opens the gateway for a remote attacker to take complete control of a user's computers.

All of the Safari bugs repaired by the update affect multiple versions of Windows XP and Vista.

One of the fixes contained in the update addresses a critical carpet bomb flaw in Safari that could enable a remote attacker to execute malicious code on an affected system if a user saved untrusted files to the Windows desktop.

The carpet bomb error became publicized May 30 after Microsoft posted a security advisory warning users of a blended threat from a combined attack exploiting a security vulnerability in Apple's Safari when used on the Windows platform.

The default download location in Safari, when combined with the way the Windows desktop handles executables, created the critical flaw that allows files to be executed and downloaded to a user's machine without their consent.

If exploited, the blended flaw could allow an attacker to unleash malicious content on a victim's computer and execute the content locally with elevated login privileges by tricking a user into visiting a malicious Web site.

To fix the issue, Apple updated Safari to prompt the user before saving a download file, and by changing the default download location to the user's Download folder on Windows Vista, and the user's Documents folder on Windows XP.

Also included in its update is a fix for another Safari error linked to two versions of Internet Explorer, which could also lead a remote attacker to execute arbitrary code.

The flaw enabled Safari to automatically launch executable files downloaded from a malicious Website while in a trusted IE zone. Specifically, users were vulnerable to remote attack if they visited a Website in IE 7 with an enabled "launching applications and unsafe files" setting, or if the visited Website was in the IE 6 "Local Intranet" or "trusted sites" zone.

To address the issue, the update prevented the automatic launching of downloaded files, while alerting the user before downloading a file if the "always prompt" setting was enabled.

Meanwhile, the Safari 3.1.2 for Windows also fixes other bugs that could lead to data exposure and malicious code execution if a user unknowingly viewed a specially crafted BMP or GIF image.

Security experts recommend that users upgrade their Safari browser with the latest update as soon as possible, which can be downloaded and installed from the Apple Web site.


RATE THIS ARTICLE Worse 1 2 3 4 5 Better
CHANNELWEB MARKETSPACE >> (Sponsored Links)
Channelweb : Promofinder
FEATURED PROMOTIONS
90% OFF Aladdin SafeWord Starter Pack - Act Now!!
Make more money with SafeWord and Aladdin now that we've joined teams. Order a SafeWord Two-Factor Authentication Starter P...
Get More in Q4 from Kaspersky Lab
Sell Kaspersky products and earn dollars for every sale of 10 or more nodes. That’s right! Every sale you make will put extra...
LATEST NEWS >>
December 01, 2008 06:50 PM
December 01, 2008 04:19 PM
December 01, 2008 03:40 PM
December 01, 2008 11:55 AM
December 01, 2008 10:39 AM
RELATED BLOG >>
Photo
The Test Center's most recent threat watch.
ADVERTISEMENT




CHANNEL SERVICES >>