RSS Vulnerability in Safari - Can we please get a patch for this

Disclosure of information vulnerability in Safari
Posted on Sun, 11 Jan 2009
Last edited Wed, 14 Jan 2009
Note: The original version of this page contained a simple workaround for this issue which I believed would protect users against this problem. I have since discovered (on 13 January 2009) that changing the default RSS feed reader application in Safari does not correctly disassociate Safari from all RSS feed URLs. The workaround section of this post has been updated with additional information. I regret that what initially appeared to be a simple workaround is now substantially more complicated and requires the installation of third-party software to perform.
I have discovered that Apple's Safari browser is vulnerable to an attack that allows a malicious web site to read files on a user's hard drive without user intervention. This can be used to gain access to sensitive information stored on the user's computer, such as emails, passwords, or cookies that could be used to gain access to the user's accounts on some web sites. The vulnerability has been acknowledged by Apple.
All users of Mac OS X 10.5 Leopard who have not performed the workaround steps listed below are affected, regardless of whether they use any RSS feeds. Users of previous versions of Mac OS X are not affected.
Users of Firefox, Camino, and Opera on Mac OS X are substantially better protected against exploitation by a malicious web page than users of Safari or OmniWeb. If users of these browsers are asked to open a link in Safari, they should not allow the request and close the page which triggered the request immediately. All users of Mac OS X may still be affected by clicking on a malicious link from their email client, instant messaging program, or another application, and should perform the workaround steps given below.
Users of Safari on Windows are also affected. Users who have Safari for Windows installed but do not use it for browsing are not affected.
The details of this vulnerability have not been made public to the best of my knowledge, but secrecy is no guarantee against a sufficiently motivated attacker.
To work around this issue until a fix is released by Apple, users should perform the following steps:
Download and install the RCDefaultApp preference pane, following the included instructions.
Open System Preferences and choose the Default Applications option.
Select the "URLs" tab in the window that appears.
Choose the "feed" URL type from the column on the left, and choose a different application or the "<disabled>" option.
Repeat the previous step for the "feeds" and "feedsearch" URL types.
The only workaround available for users of Safari on Windows is to use a different web browser.
Apple has not made information available on when a fix for this issue will be released. Users with questions or concerns should contact Apple as I have no additional information about this vulnerability which can be shared at this time.
For the curious, security issues in Mac OS X which I previously reported to Apple were fixed in Security Updates 2008-001, 2008-002, 2008-003, and 2008-004.
Reference: http://brian.mastenbrook.net/display/27

cromdubh wrote:
How come the entire Apple community isn't going APE about this issue?
What exactly do you want? Worldwide demonstrations? The Mac community to lay siege to Infinite Loop? Vulnerabilities crop up quite regularly on any OS, and fortunately less commonly on Mac OS X. Apple take security threats very seriously. I'm sure that Apple's script-smiths have been sweating 24/7 over a fix for this ever since it was brought to their attention, in the meantime FLUIDNYC has posted Brian Mastenbrook's workaround. And be grateful that there are White Hats such as B.Mastenbrook Esq who search out vulnerabilities and bring them to our attention.
Have fun,
Adrian

Similar Messages

  • Can we please get some assistance for the Tap Chat product??

    This is my second post about this matter, and yet no response at all. I bought the tap chat in hopes that it would actually work. But when I press it down, it opens up my task manager, as if I just pressed ctrl + delete. It will not work with vent, it doesnt even show up on the audio control panel for the headset. So what gives? Are your drivers not able to work on a windows 7 64-bit OS? A response from one of you guru's would be great!

    Bustler, I already posted about this problem here: http://forums.creative.com/t5/Headphones-Headsets/WoW-SB-Tap-Chat-not-working-not-visible-in-Creativ...
    The device is recognized by Windows just fine. The problem is that it's not showing up under the Creative Audio control panel. Of course Creative suppot doesn't even know the device exists so we have little support atm. I'm hoping that posting here will get this problem some visibility as calling support directly has resulted in blank stares (figuratively) from the support personell and no return calls after they have promised to research the issue and device.

  • Hi All can you please tell me solution for this error occurs

    I am trying to use Adaptive RFC model am getting following error :
    Failed to create new JCO client connection WD_RFC_METADATA_DEST: com.sap.tc.webdynpro.services.sal.sl.api.WDSystemLandscapeException: Error while obtaining JCO connection.
    This error is occuring while i am trying to create JCO connections,
    In my content administrator ,message server combo and application serber combo are showing empty why i am not understanding ?
    expecting answer asap. useful Answers will be rewarded nicely
    regarded
    jalandhar.

    Hi,
      Before using the model, u have to create JCO connection in ur application server.
    Check these links.
    Configuration of JCo
    http://help.sap.com/saphelp_nw2004s/helpdata/en/3a/3b1b40fcdd8f5ce10000000a155106/frameset.htm
    For configuring SLD, check these.
    SLD Connection
    Configuring SLD in Sneak Preview SAP NetWeaver '04 Sneak
    Regards,
    Harini S

  • Can someonoe please assist me in my Adobe Photoshop CS6 Extended.  I keep getting a 'Couldn't Complete Your Request because Dynamic Link is not Available?" Is there a way of getting a software patch for this problem?  I thought you didn't need extra softw

    Can someonee please assist me in my Adobe Photoshop CS6 Extended.  I keep getting a 'Couldn't Complete Your Request because Dynamic Link is not Available?" Is there a way of getting a software patch for this problem?  I thought you didn't need extra software.  My software other than that problem works fine.

    Couldn't complete what request?   Way more information please.
    What operating system?

  • HT1212 My iPod touch is disabled after too many attempts and I want to enable it without getting it clear so can you please help me out in this....

    My iPod touch is disabled after too many attempts and I want to enable it without getting it clear so can you please help me out in this....

    A data recovery company MAY be able to do it for a price. The Disabled is a very good security feature.
    JWhy not just restore from the last backup you have?
    Place the iOS device in Recovery Mode and then connect to your computer and restore via iTunes. The iPod will be erased.
    iOS: Wrong passcode results in red disabled screen                         
    If recovery mode does not work try DFU mode.                        
    How to put iPod touch / iPhone into DFU mode « Karthik's scribblings        
    For how to restore:
    iTunes: Restoring iOS software
    To restore from backup see:
    iOS: How to back up     
    If you restore from iCloud backup the apps will be automatically downloaded. If you restore from iTunes backup the apps and music have to be in the iTunes library since synced media like apps and music are not included in the backup of the iOS device that iTunes makes.
    You can redownload most iTunes purchases by:
      Downloading past purchases from the App Store, iBookstore, and iTunes Store

  • I have an iphone 4 and it will not boot. I've done everything except downgrade the firmware to 6.1.3 or 6.1.4... is this what needs to happen and if so can I please get a link to do so? thanks

    I have an iphone 4 and it will not boot. I've done everything except downgrade the firmware to 6.1.3 or 6.1.4... is this what needs to happen and if so can I please get a link to do so? thanks

    Hi JACOBfromINSIDEaLION,
    If you are unable to get your iPhone to restore, you will want to perform a restore from recovery mode, as explained in the following article:
    If you can't update or restore your iOS device
    http://support.apple.com/kb/HT1808
    Thanks for being a part of the Apple Support Communities!
    Cheers,
    Braden

  • Can we please get more Real Housewives?

    Can we please get more Real Housewives? There have been several shows on television already that have not been on the iTunes store, including Season 5 "The Real Housewives of New Jersey" and season 3 of "The Real Housewives of Miami." I work writing about these shows, so having them available in iTunes would definitely help out. Season passes for these seasons would be awesome.
    Also, the same thing for Rachel Zoe season 5.

    That's totally up to the owners of the rights to those shows. Contact them and urge them to work out whatever contractual difficulties are preventing them from offering those seasons through the iTunes Store.
    Regards.

  • Can anyone please help me to overccome this download error message: "Error getting License, License Server Communication Problem: E_ADEPT_DOCUMENT_OPEN_ERROR. I would be most grateful.

    Can anyone please help me to overcome this e-book download error message? It reads: "Error getting License, License Server Communication Problem: E_ADEPT_DOCUMENT_OPEN_ERROR. I would be most grateful.

    Please try de-authorizing and authorizing again.
    Steps to De-authorize
    1) Switch to Library Mode by clicking Library button
    2) Select menu item Help--> Erase Authorization or Press Ctrl+Shift+D
    3) Click Erase button to De-authorize
    Steps to Authorize
    1) Launch ADE
    2) Switch to Library Mode by clicking Library button (if you are in Reading Mode)
    3) Select menu item Help-->Authorize Computer or Press Ctrl+Shift+U
    4) Enter the valid credential to Authorize
    Hope this solves your problem.

  • X99S XPOWER AC - Can I please get a BIOS compatible with XP941 SSD

    I saw the x99s gaming 7 got some beta bios love and fixed the XP941. But I have the X99s spower AC and my XP941 is not showing in the BIOS. Can I please get a beta bios that fixes this? I want to install an OS to  it and boot from it

    I can't seem to edit my posts. Anyways, I tried installing anyways. Windows 8 saw the SSD and it was able to do the pre-install on it. After it reboots though, because the BIOS cannot see it, it cannot boot from it and continue installing. Also, I found a picture somewhere on these forums that shows to enable "pcie nand configuration" but there is no option for that in my bios, even after enabling windows 8 feature and fast foot and raid mode.
    Surely its a bios bug and i hope there is a fix already out there
    edit: Another thing that I found that I miss from my x79 big bang-xpower II motherboard is the failed OC recovery. If my OC fails on my X99S motherboard, there is no recovery. It just powers off and doesn't turn back on. If I try to turn it back on, it just turns off again after about 8 seconds. The only way to get back is to clear CMOS, which is very cumbersome. If I did the same on my old X79 board, it would revert to default settings temporarily so it could boot and would have the failed OC settings still showing in the OC options so you could quickly tweak them.
    i hope these 2 bugs/features are fixed/implemented soon. Until then, my PC cant work at its fullest potential.

  • I never  purchased an Adobe App and I'm being charged $89 for it?? Also there is a charge got $100 for storage icloud that I was OVER CHARGED for. Can someone please get in touch with me about these charges!!!  I've been waiting. Thx

    I never  purchased an Adobe App and I'm being charged $89 for it?? Also there is a charge got $100 for storage icloud that I was OVER CHARGED for. Can someone please get in touch with me about these charges!!!  I've been waiting. Thx

    Change your iTS password!!!!
    Are these charges from Adobe or Apple?
    Are these purchases from the App Store or iTunes Store?
    Contact your credit card company and dispute the charges. Apple and Adobe will do nothing for you - it is your CC issuer that can help.
    As noted these are user to user discussions. None of us here work for Apple or Adobe.
    Contact iTS Customer Service via these links - http://www.apple.com/support/itunes/
    MJ

  • Can you please help me how resolved this issue.

    Hi Experts
    I am trying to connect LDAP by R/3 system. R/3 system connected to LDAP but when I am trying to find and pull the fileds in the "Find in the Directolry" option I am getting below error.
    LDAPRC 010 another server is referenced.
    Can you please help me how resolved this issue.
    With Regards,
    Trinadh Bokka

    You may be able to solve by using
    Note 1151329 - Depth of LDAP search is only one level below the base entry
    Markus

  • How do i get a list of all Roles defubed under a particular OrganizationalUnit? How can i use LDAPConnection.search method for this?

     

    Sorry for the typographical mistake.
    Please read the question as:"How do i get a list of all Roles defined under a particular OrganizationalUnit? How can i use LDAPConnection.search method for this?"

  • HT1459 Locked my ipod and its says Ipod is disabled connect to itunes.  Have tried to unlock it - can someone please type the instructions for me to follow - thank you

    Locked my ipod and it says ipod is disabled connect to itunes - have tried everyting - can not rememb er password - can someone please type good instructions for me to get back in - thank

    Place the iOS device in Recovery Mode and then connect to your computer and restore via iTunes. The iPod will be erased.
    iOS: Wrong passcode results in red disabled screen                          
    If recovery mode does not work try DFU mode.                         
    How to put iPod touch / iPhone into DFU mode « Karthik's scribblings

  • I heard that there was a problem with Apple being vulnerable to Hackers. Has anyone seen an update for this issue? My IPad received the update last night but I have not seen anything for Safari.

    I heard that there was a problem with Apple being vulnerable to Hackers. Has anyone seen an update for this issue? My IPad received the update last night but I have not seen anything for Safari.

    Mac OS X 10.9.2 was released today for this issue and others. Earlier versions are not affected.
    See this Apple article - http://support.apple.com/kb/HT6114
    You can use the Mac app store to do the update or download it directly from here - http://support.apple.com/kb/DL1725
    Best of luck.

  • Can you please provide the information for writing ocp

    Hi,
    Iam planning to write OCP exam, can you please provide the information for it.
    what are the courses i need to take.where can i get the study material for it.
    Looking forward for your reply

    The 9i OCP track is 2 plus 2 exams plus a hands-on course. Follow the links you got above.
    The best study material, if you really want to study and get to know the stuff, is available here on OTN. Download and practice the Database together with reading the Concepts, SQL Reference, Admin and Performance tuning guides from 10g or 9i libraries.
    Use the Search to lookup concepts, syntax etc.

Maybe you are looking for

  • SUM - amount of product in all WAREHOUSEs

    Hi I am sql beginner and have a problem with collecting data from Oracle DB. I have a table ODT with all the products (nr of product and nr of warehouse are the PK) (NTWR and NODD). for every warehouse the product has its row. for example product nr

  • Slow and insecure but feature-rich pacman wrapper in bash

    This project of mine started because I want to compile my packages in a way that lets me delete gnome apps. Here's the problem: I see that evince depends on gnome-keyring, gnome-keyring depends on gconf and alltray depends on gconf. This leads me to

  • Post-upgrade tasks for OWB 10g Release 2

    Hi, we're planning to upgrade from OWB 10.1.0.2 to 10.2.x. Now, I'm trying to get a clear view on what will be the "post-upgrade" tasks, in terms of manual adaptations, corrections, etc. to get everything back up and running after the upgrade ... E.g

  • Discount on A/P invoice

    experts, How can we determine what account being use when we have a discount on AP invoice

  • Moving domain name from one plan to another

    Hi guys, I am about to go live with my new partner site - hopefully today. However since there was no practical way to redo the free partner site - I decided I would just upgrade to a paid account. So my question is, as I will have to move my domain