Let's get started!

Initializing...



Tuesday, February 21, 2006

MAC OSX security vulnerability

This post is for Joe, and all of you other mac users. I think this was the security hole Joe emailed me about, but I think the email only stated that one must open the malicious doc or email for it to take effect. This article goes further saying:

"It can also be exploited automatically by Safari when visiting a malicious website."-Macworld UK

"Secunia has constructed a test, which can be used to check if your system is affected by this issue:
http://secunia.com/mac_os_x_command_execution_vulnerability_test/

The vulnerability has been confirmed on a fully patched system with Safari 2.0.3 (417.8) and Mac OS X 10.4.5.

Solution:
The vulnerability can be mitigated by disabling the "Open safe files after downloading" option in Safari.

Do not open files in ZIP archives originating from untrusted sources."

-Secunia