Stories
Slash Boxes
Comments
typodupeerror delete not in

+-   Safari 3.1 for Windows found vulnerable -> on Thursday March 27 2008, @01:26AM recoiledsnake

Submitted by recoiledsnake on Thursday March 27 2008, @01:26AM
programming
recoiledsnake writes "The new Safari 3.1 for Windows has been hit with two 'highly critical'(as rated by Secunia) vulnerabilities that can result in execution of arbitrary code. The first is due to an improper handling of the buffer for long filenames of files being downloaded and the second can result in successful spoofing of websites and phishing. This comes close on the heels of criticism of Apple for Safari being offered as a update for approximately 500 million users of iTunes on Windows by default and reports of crashes . There are currently no patches or workarounds available except the advice to stay clear of 'untrusted' sites."
Link to Original Source
submission

This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More
Loading... please wait.
if (rsfp = mypopen("/bin/mail root","w")) { /* heh, heh */ -- Larry Wall in perl.c from the perl source code