Follow the Australian Telecommunications scene NEWSLETTER- FREE TRIAL
Core Dump
Core Dump RSSStephen Withers turns his gaze on the world of Apple, with detours into other aspects of IT and communications as they catch his attention.
Technology news and Jobs arrow Our Blogs arrow Core Dump arrow Safari vulnerable to remote file-stealing attack
Safari vulnerable to remote file-stealing attack E-mail
by Stephen Withers   
Tuesday, 13 January 2009
Windows users should simply use a different browser, Mastenbrook suggests.

Mastenbrook has previously been credited by Apple for reporting Mac OS X vulnerabilities.

His record includes spotting a way of triggering an Applescript with a specially-crafted Help: URL (Security Update 2008-002), and suggesting improvements to the list of quarantined file types (Mac OS X 10.5.3 and 10.5.4, and Security Update 2008-003 and 2008-004),

The public disclosure of vulnerabilities before a fix has been released by the vendor concerned is a contentious issue.

One school of thought says that the responsible thing to do is keep completely quiet until the vendor has issued an update to take care of the issue.

Another holds that if one person can find a particular flaw, so can another. Therefore unless a fix is released promptly by the vendor, the right thing to do is alert users to the problem and provide a workaround so they at least have the opportunity to protect themselves.

Mastenbrook gave no indication of when he alerted Apple to this vulnerability.

Powered By Joomla Tags

Please enable JavaScript in your browser to post your comment!



 
< Next story in category   Previous story in the category >
iTWire user statistics Visitors last 30 days
694,279
Subscribers 15,210
#1 independent technology news advertise here
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff

- Advertisement -

Featured Whitepapers

Follow iTWire on Twitter

About iTWire

iTWire is all about technology news, information, jobs and community for the IT and telecommunications industry professional. Subscribe to our free ICT daily newsletter