Safari, IE flaw could allow malicious code execution
Macworld -
In what is being described as a "highly critical" vulnerability, security firm Secunia on yesterday issued an advisory to all Mac OS X users that surf the Web with Microsoft Corp.'s Internet Explorer or Apple Computer Inc.'s Safari Web browsers.
The vulnerability, which was first reported by lixlpixel and confirmed by Secunia, takes advantage of the "help" URI handler and "allows execution of arbitrary local scripts (.scpt) via the classic directory traversal character sequence using 'help:runscript.'"
The result of the vulnerability, which has been confirmed using Safari 1.2.1 (v125.1) and Internet Explorer 5.2, is that it is "possible to place arbitrary files in a known location, including script files, on a user's system if the Safari browser has been configured to ("Open "safe" files after download") (default behavior) by asking a user to download a ".dmg" (disk image) file."
Secunia recommends opening Safari preferences and uncheck "Open 'safe' files after download.
Reprinted with permission from
Story copyright 2009 Mac Publishing, LLC. All rights reserved.
Macintosh
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Southern Company
Download Now
Extending Client Refresh - 11 Steps to Maximize Savings
Register Now!
Defending Against the Storm
Download Now
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Share our Strength
Download Now
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Consolidate Your Servers and Storage to Lower Costs with Oracle Database 11g
Register for this webcast!
Top 10 Things to Know about Data Protection
Download Now
The Commercialization of ITIL: Lessons Learned
Register for this event today!
