The Channel logo

News

By | John Leyden 23rd June 2008 12:34

Threat remains despite Safari carpet bombing fix

Blended beastliness

Apple finally fixed a "carpet bombing" flaw in the Windows version of its Safari web browser, but security researchers warn that the consumer electronics giant's patch only provides partial relief from bugs involving the interaction of Safari and other browser packages.

A flaw that meant Safari automatically downloaded executable files based on IE zone settings was one of three vulnerabilties in the browser addressed in an update published by Apple on Thursday.

The other two updates addressed errors in processing image files that created a memory disclosure risk and a memory corruption flaw involving the handling of JavaScript arrays.

Upgrading to version 3.1.2 addresses all three bugs, according to Apple.

However, security researcher Billy Rios warns that the "carpet bombing" fix is only partial. If Safari is used on a system where Firefox is also installed it might be possible to steal arbitary files, he warns. The flaw, like the carpet bombing bug before it, involves a blended threat concerning how Safari and other browser packages work together. Rios is holding back details of the bug pending a release from Apple. ®

comment icon Read 7 comments on this article alert Send corrections

Opinion

Memristor_wafer

Chris Mellor

Execution warrant close to being signed for Fink's folly
Woman cuddles 'sly-looking' Fennec fox. Photo by Shutterstock
Cartoon of employee asking wky boss makes hium wear suspenders (while pincer through open trapdoor remains poised above his head) illustration by Cartoon resource for Shutterstock

Frank Jennings

It's not like my boss painstakingly nurtured the contacts, right?

Features

Girl and computer, photo via Shutterstock
Middle-class terror of engineering also part of problem
Nerd fail photo via Shutterstock
Shouting match
Single market vs. rest of the world