AppleInsider AppleInsider Forums


Go Back   AppleInsider > Applications
Register Members List New Posts Mark Forums Read

Reply
 
Thread Tools Display Modes
Old 01-13-2009, 09:33 AM   #1
AppleInsider
Kasper's Automated Slave
 
Join Date: Nov 1997
Posts: 6,151
Security flaw in Safari's RSS feeds reported

An open source software engineer says he's found a vulnerability in Safari for Mac and Windows that could compromise a user's files and passwords if successfully exploited.

Brian Mastenbrook didn't get specific in a*blog entry*posted Sunday, but he did claim his discovery has already been acknowledged by Apple.* All users of Mac OS X 10.5 Leopard are affected, whether they use RSS feeds or not, as long as they have not changed their preference from the default, as seen below.

"Safari ... is vulnerable to an attack that allows a malicious web site to read files on a user's hard drive without user intervention," Mastenbrook wrote.* "This can be used to gain access to sensitive information stored on the user's computer, such as emails, passwords, or cookies that could be used to gain access to the user's accounts on some web sites."

According to Mastenbrook, Mac OS X Leopard users should change their Default RSS reader preference to another feed reader.* Possible solutions include Mail and*NetNewsWire.

Safari for Windows users should use a different web browser until the security hole is patched, he said.



Mastenbrook has a credible reputation for bug reporting, with*no*fewer*than*four*mentions,*by name, in previous Apple release notes.
AppleInsider is offline   Reply With Quote
Old 01-13-2009, 09:44 AM   #2
camroidv27
Registered User
 
Join Date: Nov 2006
Location: Arizona
Posts: 329
Just goes to show that ALL software has the potential of being compromised. Windows, Mac OS, Linux, whatever...

For all Safari users, I hope Apple releases a quick fix.


openSuSe 11.2, 32 and 64 bit, for Mac and PC!
"Shiny capt'n. Everything thing is A-Okay."
camroidv27 is offline   Reply With Quote
Old 01-13-2009, 09:59 AM   #3
vandil
Registered User
 
Join Date: Jan 2009
Posts: 96
What's funny is that RSS used to be this huge thing back in like 2003. I never got into it, I simply visit a specific list of bookmarks each day. Maybe that's old school, but I guess its "more secure".
vandil is offline   Reply With Quote
Old 01-13-2009, 10:32 AM   #4
pmjoe
Registered User
 
Join Date: Jan 2005
Posts: 562
Well, if we're suggesting other RSS viewers/readers, let me put in a plug for Vienna. Switched to it a couple of years ago and never looked back. It's free, specific to the Mac, and open source. So open that I've even mucked around with how it displays the feed items a bit to meet my preferences.

http://www.vienna-rss.org/

That said, it's certainly possible that other readers have their own security flaws.
pmjoe is offline   Reply With Quote
Old 01-13-2009, 12:42 PM   #5
archer75
Registered User
 
Join Date: Jan 2005
Posts: 167
I use reader.google.com

Works great.
archer75 is offline   Reply With Quote
Old 01-13-2009, 01:12 PM   #6
lkrupp
Registered User
 
Join Date: Jan 2005
Posts: 261
Quote:
Originally Posted by pmjoe View Post
Well, if we're suggesting other RSS viewers/readers, let me put in a plug for Vienna. Switched to it a couple of years ago and never looked back. It's free, specific to the Mac, and open source. So open that I've even mucked around with how it displays the feed items a bit to meet my preferences.

http://www.vienna-rss.org/

That said, it's certainly possible that other readers have their own security flaws.
I'm just sticking with Safari as my RSS reader. I don't plan on crawling under my bed in fear.
lkrupp is offline   Reply With Quote
Old 01-13-2009, 02:06 PM   #7
mstone
Registered User
 
Join Date: Jan 2006
Location: SoCal
Posts: 930
Quote:
Originally Posted by archer75 View Post
I use reader.google.com

Works great.
reader.google.com is a web page. I think the point is that if you are using Safari to view web pages, you need to make the change to your preferences.

Quote:
All users of Mac OS X 10.5 Leopard are affected, whether they use RSS feeds or not, as long as they have not changed their preference from the default.
mstone is offline   Reply With Quote
Old 01-13-2009, 02:06 PM   #8
mdriftmeyer
Registered User
 
Join Date: Nov 2004
Location: Northwest
Posts: 2,695
He targets 10.5 users.

What about the RSS design for 10.5 that makes 10.4.x not necessarily reported?

He should test this "vulnerability" with Safari Developer 4.x. If it's available he should contact ADC and report that it's still there in trunk. If not, he should be clear that it's been fixed upstream and urges Apple backport it downstream to Safari 3.2.1 with a new version, Safari 3.2.2.
mdriftmeyer is offline   Reply With Quote
Old 01-13-2009, 04:51 PM   #9
Eideard
Registered User
 
Join Date: Mar 2008
Location: Santa Fe
Posts: 11
Quote:
Originally Posted by lkrupp View Post
I'm just sticking with Safari as my RSS reader. I don't plan on crawling under my bed in fear.
Ditto!
Eideard is offline   Reply With Quote
Old 01-13-2009, 05:28 PM   #10
jwervel16
Registered User
 
Join Date: Oct 2008
Posts: 30
Quote:
Originally Posted by camroidv27 View Post
Just goes to show that ALL software has the potential of being compromised. Windows, Mac OS, Linux, whatever...
You said it, Bill! On the one hand, an untested RSS browser hack; on the other, an OS crawling with bugs and viruses requiring constant flushing, patches, security applications, and a near daily dose of restarts and uncertainty. Yep, same diff!
jwervel16 is offline   Reply With Quote
Old 01-13-2009, 07:26 PM   #11
ascii
Registered User
 
Join Date: Feb 2005
Posts: 791
It's not very difficult to parse an XML file and render it. I really don't see how you could have a security hole in a piece of code like that, unless you are really just not paying attention.
ascii is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 11:13 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.