Advertisement
Promo

Security threats Toolkit

Unpatched Safari bug exposes sensitive info

Matthew Broersma ZDNet.co.uk

Published: 14 Jan 2009 15:57 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Apple's Safari browser on Windows and Mac OS X is vulnerable to a bug that could allow a malicious website to read files on the user's hard drive, according to a security researcher.

The flaw is related to the way Safari handles web feeds such as RSS, but it affects users even if they do not use feeds, researcher Brian Mastenbrook wrote in an advisory published on Sunday. Feeds are a data format used for notifying users of frequently updated content, such as blog posts.

The vulnerability could be used to read sensitive information, such as passwords, on a user's system, Mastenbrook said. An attack could be triggered via a malicious link opened in Safari on either Windows or Mac OS X 10.5, he said. Other versions of Mac OS X are not affected.

Apple has acknowledged the flaw, but has not yet indicated when it will be patched, according to Mastenbrook. "The details of this vulnerability have not been made public to the best of my knowledge, but secrecy is no guarantee against a sufficiently motivated attacker," he wrote in an advisory.

As a workaround, Mac OS X users can change the system's preferences to use an application other than Safari for reading feeds. However, the operating system's built-in method for changing feed reader preferences does not correctly disassociate Safari from feeds, Mastenbrook said.

In a post on Tuesday, he recommended the use of a third-party application such as RCDefaultApp to perform the workaround.

The only workaround available to Safari users on Windows is to use a different browser, Mastenbrook said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?


Full Talkback thread

1 comment

  1. Yikes David D

Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters