On CBSNews.com: Can 365 Nights Of Sex Fix A Marriage?
BNET Business Network:
BNET
TechRepublic
ZDNet

May 30th, 2008

Microsoft issues Safari-to-IE blended threat warning

Posted by Ryan Naraine @ 5:16 pm

Categories: Patch Watch, Hackers, Apple, Microsoft, Windows Vista, Browsers, Vulnerability research, Responsible disclosure, Exploit code, Arbitrary Code Execution, Complex Attacks

Tags: Apple Safari, Microsoft Corp., Microsoft Windows, Web Browsers, Operating Systems, Security, Software, Internet, Ryan Naraine

Microsoft issues Safari-to-Windows blended threat warningMicrosoft has issued a formal security advisory with a confirmation of public warnings that the Safari “carpet bombing” vulnerability presents a remote code execution threat on all supported editions of Windows XP and Windows Vista.

The pre-patch advisory from Redmond follows public pressure from the Google-backed StopBadware.org for Apple to rethink its stance that the Safari issue should be considered a serious security vulnerability.

From the Microsoft advisory:

A combination of the default download location in Safari and how the Windows desktop handles executables creates a blended threat in which files may be downloaded to a user’s machine without prompting, allowing them to be executed.

…An attacker could trick users into visiting a specially crafted Web site that could download content to a user’s machine and execute the content locally using the same permissions as the logged-on user.

 [ SEE: Why Apple must fix Safari ‘carpet bombing’ flaw immediately ]

According to the advisory, the Windows portion of the blended threat is linked to Internet Explorer (IE 6 and IE 7 on Windows XP and Windows Vista, all service packs included).    Technical details on the combo-threat are being kept under wraps but it is clear that Microsoft has

actual proof of an IE vulnerability can be used in tandem with Nitesh Dhanjani’s Safari bug to launch a malicious executable if a user surfs to a rigged site with Safari.

Officials in the MSRC (Microsoft Security Response Center) held discussions with Apple before releasing the advisory.

[ SEE: Apple under pressure to fix Safari ‘carpet bomb’ flaw ]

As a temporary mitigation, Microsoft recommends that Windows uses restrict the use of Safari as a web browser until an appropriate update is available from Microsoft and/or Apple.

Alternatively, if you must use Safari, you should change the download location of content in Safari to a location other than ‘Desktop’.   This can be done by launching Safari and using the Edit > Preferences and selecting a different location on the local drive for  Save Downloaded Files to: option.

My previous advice stands.  Uninstall Safari and use an alternative browser on Windows.

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the world. See his full profile and disclosure of his industry affiliations.

Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

  • Talkback
  • Most Recent of 55 Talkback(s)
Why in the world would ANYONE use Safari on Windows?
There are plenty of far superior alternatives. What's the point? (Read the rest)
Posted by: butler360 Posted on: 06/25/08 You are currently: Logged In | Log out
I don't get it Yagotta B. Kidding   | 05/30/08
Windows: .exe = executable AySz88   | 05/30/08
Confirmation... Spiritusindomit@...   | 06/02/08
RE: Microsoft issues Safari-to-IE blended threat warning ZachE84   | 05/30/08
M$ issues Safari warning bfilipiak@...   | 06/02/08
Same Situation, Different Day _dietrich   | 05/30/08
Doesn't that just open a whole other Pliny the Elder   | 05/30/08
Great questions _dietrich   | 05/31/08
Ergh... nmcfeters   | 06/03/08
ZZZZZZZZZZ...nt socialism=nowhere   | 06/02/08
damn right rebelxhardcore   | 06/02/08
Oh the irony... zkiwi   | 05/30/08
Really, really ironic.. silent.griffin   | 05/31/08
Don't try and say advertising is the same as an advisory (nt) zkiwi   | 05/31/08
Yep, they're different. silent.griffin   | 06/01/08
Yet they don't advise people... zkiwi   | 06/01/08
Damn it. I never learned. silent.griffin   | 06/01/08
Label away... zkiwi   | 06/01/08
The difference between advertising and advisories Hemlock Stones   | 06/02/08
@hemlock zkiwi   | 06/02/08
The advisory is a bit specious, but... bmerc   | 06/02/08
Nice word... zkiwi   | 06/02/08
The difference being tikigawd   | 06/02/08
Your'e missing the bit about Microsoft's suggested workaround zkiwi   | 06/02/08
This is better rtk   | 05/30/08
And... Qbt   | 05/31/08
They way I read it is.. A Grain of Salt   | 05/31/08
No extra click required Ryan Naraine  ZDNet | 05/31/08
Well.. ZachE84   | 05/31/08
Firefox has had it's share of problems nmcfeters   | 06/03/08
I would not consider any vulnerability frgough   | 06/02/08
Could you provide some more info? balaknair   | 06/02/08
You misunderstood his post cslycord@...   | 06/02/08
OK, thanks for clarifying balaknair   | 06/03/08
What he means is tikigawd   | 06/02/08
Seems like it (: P) balaknair   | 06/03/08
Would uninstalling IE help? visoot   | 06/04/08
Stupid me! visoot   | 06/05/08
Good points but for the end nilotpal_c   | 05/31/08
IS there any reason why Windows Desktop should be executing files? (nt) CobraA1   | 06/02/08
You have to think of Windows desktop alaniane@...   | 06/02/08
Safari is a joke anyway masonwheeler   | 06/02/08
I'm sorry but, CowLauncher   | 06/02/08
Spreading FUD? masonwheeler   | 06/02/08
I tried Firefox and went straight back to Safari labarker   | 06/02/08
RE: Microsoft issues Safari-to-IE blended threat warning support1@...   | 06/02/08
64-bit is no panacea. In fact, a MAJOR malware exploit can ONLY be 64-bit! Joel R   | 06/02/08
Well... Spiritusindomit@...   | 06/02/08
huh? Deviros   | 06/02/08
And so say all of us. odubtaig   | 06/02/08
That was my thinking laura.b   | 06/03/08
RE: Microsoft issues Safari-to-IE blended threat warning jerang@...   | 06/02/08
RE: Microsoft issues Safari-to-IE blended threat warning thrasher6900@...   | 06/05/08
Don't you mean laura.b   | 06/06/08
Why in the world would ANYONE use Safari on Windows? butler360   | 06/25/08

What do you think?

No Trackbacks Yet

The URI to TrackBack this entry is:
http://blogs.zdnet.com/security/wp-trackback.php?p=1230

advertisement

Recent Entries

advertisement

Archives

ZDNet Blogs

All-in-One Printers

advertisement
Click Here