Skip to main content

Tue, 21 Feb 2006 Safari struck by Zip security warning

Macworld staff


  • Email to a friend
  • Print this article
  • Bookmark this page
  • RSS feed

A new security vulnerability in Safari has been identified by security experts at Secunia.

The company - which rates the flaw as “extremely critical” - says that the vulnerability was discovered by a source outside the company, Michael Lehn.

It can be exploited by malicious people to compromise a user's system, it warns.

The vulnerability is caused by an error in the processing of file association meta data (stored in the "__MACOSX" folder) in ZIP archives.

“This can be exploited to trick users into executing a malicious shell script renamed to a safe file extension stored in a ZIP archive,” Secunia warns.

It can also be exploited automatically by Safari when visiting a malicious website.

The company has released a test users can run to check if their system has been affected.

The vulnerability has been confirmed on an up-to-date system running Safari 2.0.3 (417.8) and Mac OS X 10.4.5.

Users can mitigate the threat by disabling the "Open safe files after downloading" option in Safari.

Email A Friend

Email this article to a friend or colleague:



PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

<<prev article | back to news index | next article>>

Question of the day!

Mark Hattersley
Editor in Chief

Do you use Adobe Photoshop with a Wacom tablet?

Question of the day!

Do you use Adobe Photoshop with a Wacom tablet?

% of Macworld readers agree with you

Yes
TBC
No
TBC

How does a Wacom tablet improve the Photoshop experience?

124 characters remaining

Follow the conversation at @TabletChat

paintings & illustrations, mostly, which i upload to flickr.RT @fragmentedm

I draw manga/anime characters. I also do graphic design and photography.RT @spialelo

Yes. I usually put them up on my #deviantart account for feedback on how to improve.RT @spialelo


Latest News


More news...