Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Apple > Software

May 16th, 2008, 08:58 GMT · By

Safari Vulnerable! Apple to Issue Fix for One of Three Faults

SHARE:

Adjust text size:



Enlarge picture
A recent report claims that Apple's security team has "dismissed" a research saying its standard web browser still has faults that may allow hackers to mess up your Mac, or PC. That's right, PC, because Apple's Safari
is available on Windows too and folks "updating" their software a while ago were in a position of finding themselves downloading malicious content, without being asked for permission by Safari. A total of three faults have been acknowledged by researchers, but Apple will be fixing only one.

"Malware downloaded to the user's desktop without the user's consent" is the primary issue researcher Nitesh Dhanjani has encountered with Apple's standard web browser on Mac OS X Leopard. According to the research, it is actually quite simple to use the browser to deploy malware on one's machine.

Malware downloaded to the user's desktop without his/her consent
Enlarge picture
According to the researcher, Safari doesn't bother to ask users for permission when downloading content from websites. Since Safari does not know how to render the content-type of a certain address, it will automatically start downloading the "carpet bomb" every time it is served. Dhanjan says this is what will happen if you are using Safari in Windows (click the image above to enlarge).

According to The Register, "when informed of this 'carpet bombing' vulnerability (as researcher Billy (BK) Rios has dubbed it), Apple agreed that it might be good if Safari actually checked with the user before downloading potentially vicious files, but signaled that kind of addition wasn't much of a priority."

An insider from Apple's security team told Dhanjani the following: "Please note that we are not treating this as a security issue, but a further measure to raise the bar against unwanted downloads. We want to set your expectations that this could take quite a while, if it ever gets incorporated."

Apple let Dhanjan know that they would fix one of the issues he reported, but asked him not to discuss the vulnerability until they roll out the fix, due to the risky nature of the bug affecting Safari on both OS X and Windows.

Secunia rates the vulnerability as "less critical."

TELL US WHAT YOU THINK:

1,845 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Kaspersky 'Unable' to Provide Unlocked iPhone Users with Protection

Safari 3.1.1 Still Not Safe. URL Spoofing Flaw Confirmed

Safari 3.1.1 Fixes PWN 2 OWN Flaw and Other Security Issues

QuickTime (7.4.5) Security Patch Detailed

Apple's Approach with the AppStore Detailed

READER COMMENTS:


Comment #1 by: k661940 on 17 May 2008, 16:43 UTC reply to this comment

yeh safari has been crashing on a regular basis i bought a mac to get away from microsoft/windows crap. seems 21st tech still cant do what the ads promise

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM