Apple Fixes Safari 'carpet Bomb' Bug

By Robert McMillan

Thu, June 19, 2008 — IDG News Service —

Apple has reversed course and patched a bug in its Safari browser after security researchers showed how it could be used to run unauthorized software on a Windows machine.

The "carpet bomb" bug, which was originally discovered by security researcher Nitesh Dhanjan, was initially thought to be less serious than it turned out to be.

Dhanjan showed how Safari could be misused to litter a victim's desktop with downloaded programs, but two weeks after he disclosed his research, another hacker, named Aviv Raff, showed that this flaw could be exploited in tandem with other problems in Windows and Internet Explorer to run unauthorized software on a victim's PC.

That prompted Microsoft to issue its own warning about the issue. It also caused some security experts to caution Web surfers about using Safari on the Windows platform.

According to Dhanjan, Apple initially told him that it did not intend to fix the issue, but apparently the company has now changed its mind.

Apple fixed the issue in the 3.1.2 version of its Safari browser for Windows, which was released Thursday afternoon. This update addresses a total of four security issues in Safari, including bugs in the way Safari renders JavaScript arrays and handles the downloading of executable files.

It also fixes a less-critical issue in the way Safari renders Bitmap and Gif images, which could give attackers a peek at the memory of a victim's computer, Apple said.

Thursday's update was for Windows computers only, and Apple has not yet released a 3.1.2 Safari update for the Mac.


Loading...
Applications MarketSpace
Service Level Reporting and Communication
Service level reporting is the most visible output and often the most time-consuming activity in SLM. Learn more »
Lower IT Costs with Oracle Database 11g Release 2
Learn how upgrading to Oracle Database 11g Release 2 can transform your business, budgets, and service levels Learn more »
Managing Your SAP System
Learn how to more effectively manage your SAP system. Learn more »
 
SPONSORED LINKS
 

White Paper: 4 Customer Service Myths

White Paper: Improve Agility with Operational Responsiveness

Removing the Barriers to IT Governance: How On-Demand Software Changes the Game

Cloud Computing--Latest Buzzword or a Glimpse of the Future?

A Balanced Approach to an Application Development Platform

Adobe® LiveCycle®solutions for intuitive user experience

10 Ways Excel Drives More Value from Your SAP Investment

What's New in SOA Suite 11g?

Unleash the Power of Java with Oracle JRockit Real Time

SOA Best Practices and Design Patterns

Application Grid: Ideal Platform for IT Consolidation

Ready to virtualize tier one applications? Check your virtualization maturity.

Learn how to provide complete Business Service Management.

Increase ROI of Your Application Portfolio

See how AT&T can help protect your network.

Top Five CIO Challenges

Streamline IT Costs. Boost Performance with WAN Optimization.

Want to know how you can maximize employee productivity?

Build your 1st app FREE with Force.com

TDWI checklist helps define data readiness for analytics. Download report.

A new fleet of PCs with a total ROI in 10 months. Find your ROI.

eZine: A Roadmap to Reducing IT Complexity

Reduce risk, gain agility. See how Progress can help your business.

Virtualization Technology as a Business Solution

eZine: A Roadmap to Reducing IT Complexity

White Paper: Managed Security for a Not-So-Secure World

SharePoint - Unchecked growth of content is unsustainable.

Focus Under Pressure: Why IT Governance Becomes Mission-Critical in a Down Economy

Should Your Email Live In The Cloud? A Comparative Cost Analysis

Adobe® LiveCycle® solutions for business process automation

Architecting Business Intelligence Applications for Change: The Open Solution

Increase UPS efficiency without sacrificing protection.

Unlocking the Mainframe: Modernizing Legacy System to SOA

State of the Data Integration Market

Enhance Customer Loyalty through Higher Responsiveness

Achieving Business Agility with Application Grid

Seven Ways ITIL Can Help You in an Economic Downturn

Four steps to populate your CMDB.

"Enterprise-Proven" is the Prerequisite for Enterprise SaaS Portal Solutions

Join us at the US-Brazil IT-BPO Summit, on November 10th in New York.

Unified Communications: Thoughts, Strategies and Predictions. Join the discussion

Read the RSA report: Security for Business Innovation

Webcast: Looking to the Cloud for Email and Collaboration Services

64-page prescriptive guide to security, compliance, and IT operations.

Keep your IT expertise up to date. Join the Intel Premier IT Professionals.

A Clear View Toward Virtualization

Virtualization Technology as a Business Solution

The rules of infrastructure management just changed.

A Clear View Toward Virtualization

Interactive Q&A helps you discover key ways to maximize IT assets.

 
 
RESOURCE CENTER