stargeek
PHP news website logo.
home    PHP scripts    articles    seo tools    links    search    contact    shop    realtors


Mac OS X Flaw Still Unfixed, Says Security Firm







Mac OS X Flaw Still Unfixed, Says
Security Firm

Mac OS X Flaw Still Unfixed, Says
Security Firm
05/25/2004 11:54 AM

  • MacCentral: Mac users still not safe from vulnerability. "What is really critical is the fact that Apple did not address the "disk" URI vulnerability, which allows malicious websites to silently place code on a user's system," said Rasmussen. "Everything should be OK, after the "help" vulnerability has been fixed, but another very unfortunate feature has been revealed in Mac OS X disk image and volume handling, allowing a disk image to register a new URI handler and associate an application with this - obviously this application can be located on the disk image or volume."



  • This is a GrokNews Entry: (what is grok?)





    Similar Items

    Mac OS X Flaw Still Unfixed, Says Security Firm

    Grok Headline matches for Mac OS X Flaw Still Unfixed, Says Security Firm

    Security firm warns of new IE flaw


    Security firm warns of new IE flaw 01/28/2004 06:39 PM
    A security services company points out a new vulnerability in Microsoft's Internet Explorer Web browser that could allow Web surfers to be tricked into downloading malicious files.

    Yahoo! Patches Security Flaw in
    Messenger August 13 - 9:38 PM ET News in
    Brief | Yahoo! has patched a flaw in


    Yahoo! Patches Security Flaw in
    Messenger August 13 - 9:38 PM ET News in
    Brief | Yahoo! has patched a flaw in
    08/14/2004 01:01 AM
    BetaNews Aug 14 2004 4:13AM GMT

    Firm Reports New Internet Explorer Flaw


    Firm Reports New Internet Explorer Flaw 10/15/2002 10:19 AM
    GreyMagic Software details an Internet Explorer browser flaw that lets attackers steal cookies from any site, forge content, read local files and execute arbitrary programs.

    Open source firm releases patch for IE
    spoofing flaw


    Open source firm releases patch for IE
    spoofing flaw
    12/19/2003 11:23 AM
    An open source and freeware software development web site has released a patch to fix the URL spoofing vulnerability in Internet Explorer, which can be exploited by scammers who try to trick people into revealing details of online banking accounts or other private information. Openwares.org, a Vaunatian company, with branches in Israel, the US and France, released the patch and the source code for the same a couple of days back. The company has also set up two pages where users can test to see if they are vulnerable to the exploit, one a fake Microsoft Update example and the other an example of a fake PayPal site.

    Open source firm releases patch for IE
    spoofing flaw - theage.com.au


    Open source firm releases patch for IE
    spoofing flaw - theage.com.au
    12/20/2003 06:23 AM
    Open source firm releases patch for IE spoofing flaw .. released a patch .. esta notcia .. Full Story .. that's

    theage.com.au/articles/2003/12/18/1071337072117.html
    track this site | 6 links


    Potential Security Flaw in Symantec
    Gateway Security 360R


    Potential Security Flaw in Symantec
    Gateway Security 360R
    06/09/2004 02:01 PM
    Dev Null (Jun 08 2004)

    RE: Potential Security Flaw in Symantec
    Gateway Security 360R


    RE: Potential Security Flaw in Symantec
    Gateway Security 360R
    06/11/2004 09:53 AM
    Symantec Product Security Team (Jun 10 2004)

    Security Flaw


    Security Flaw 12/11/2003 10:53 AM

    While a security hole in IE gets Slashdot coverage, its seems that this particular security hole can affect not only IE, but also Mozilla 1.5.

    Demonstration: not yahoo


    Mozilla Security Flaw


    Mozilla Security Flaw 07/08/2004 08:27 PM

    eWeek reports on a new browser security flaw that enables links to run arbitrary programs - but this time the problem isn't in IE, but in Mozilla (and therefore Firefox). As expected, the Mozilla team has already released a fix.


    AOL AIMs to fix security flaw


    AOL AIMs to fix security flaw 08/11/2004 11:41 AM
    Buffer the IM Slayer

    Security flaw in rssh


    Security flaw in rssh 06/21/2004 11:33 PM
    Derek Martin (Jun 19 2004)

    IRS admits security flaw


    IRS admits security flaw 07/20/2004 07:43 AM

    New Microsoft IE security flaw


    New Microsoft IE security flaw 12/19/2004 02:56 PM
    p2pnet.net Dec 19 2004 4:48PM GMT

    WinZip offers fix for security flaw


    WinZip offers fix for security flaw 09/07/2004 10:42 AM
    But users of the popular compression tool will need to upgrade to version 9 of the software and pay a license fee.

    WinZip patches security flaw


    WinZip patches security flaw 09/06/2004 02:14 PM
    ZDNet UK Sep 6 2004 6:45PM GMT

    Notes and Tips: More on Security Flaw


    Notes and Tips: More on Security Flaw 05/21/2004 10:07 AM
    Readers have more tips and questions about the Mac OS X security problem.

    Apple tackles Mac security flaw


    Apple tackles Mac security flaw 05/24/2004 04:40 AM
    Apple users have been updating their software to close a hole which could expose Macs to attack.

    Online banks hit by old security flaw in
    IE


    Online banks hit by old security flaw in
    IE
    07/01/2004 05:25 AM
    I-ring.com - Thu Jul 1, 08:57 am GMT

    Help: security flaw hits mainstream


    Help: security flaw hits mainstream 05/19/2004 06:02 PM
    If you browse the internet (since you read this, that means you), watch out for the latest OS X exploit. It seems to only be a problem in Panther. The help: protocol can be abused to launch AppleScripts. Why is this bad? Terminal commands can be called from AppleScript. In other words, simply visiting a web page can do serious damage. A proof of concept (harmless, but scary) is located here. What can you do? Download an application like More Internet or GURLfriend and remap the help protocol. If you have any tips, please leave a comment.

    Update: NetNewsWire might also be affected, though it is rare you would subscribe to a feed that wants to erase your hard drive.

    New IE Security Flaw Exposed
    (NewsFactor)


    New IE Security Flaw Exposed
    (NewsFactor)
    07/07/2004 03:00 PM
    NewsFactor - A Dutch computer science student claims that Microsoft's (Nasdaq: MSFT) latest patch for its Internet Explorer browser, released July 2nd, does not provide sufficient protection. In an Internet News Group posting, Jelmer Kuperus says he has found another way hackers could run malicious programs on a Web user's PC.

    Image flaw pierces PC security


    Image flaw pierces PC security 08/05/2004 07:17 PM
    ZDNet Aug 5 2004 11:31PM GMT

    Security Flaw Discovered in Firefox


    Security Flaw Discovered in Firefox 04/05/2005 02:57 PM
    Security firm Secunia has discovered a "moderately critical" security flaw in the most recent versions of Firefox and the Mozilla Suite. According to the advisory, a problem in the handling of JavaScript could potentially allow a remote user access to sensitive information. The bug was fixed within hours of its initial report.

    Cobalt RaQ 4 Security Flaw Detected


    Cobalt RaQ 4 Security Flaw Detected 12/12/2002 10:51 AM
    An exploit of this vulnerability is publicly available and affected server admins are urged to immediately apply fixes.

    OS X Security Flaw Plagues Web Browsers


    OS X Security Flaw Plagues Web Browsers 05/20/2004 09:55 AM
    In an exclusive interview, "lixlpixel," the person who discovered the flaw said that after waiting on Apple's reply, he finally posted the advisory to a Swiss Macintosh Web site. "This is how Secunia picked up on the vulnerability," lixlpixel said. By Blane Warrene, MacNewsWorld (via MyAppleMenu)

    Internet Jeopardized by Serious Security
    Flaw


    Internet Jeopardized by Serious Security
    Flaw
    04/20/2004 06:17 PM
    There has been some very secretive work over the last few months with multi-national governments to fix the TCP flaw....

    Serious Linux Security Flaw Found


    Serious Linux Security Flaw Found 12/02/2003 02:35 PM
    The bug affects versions of the Linux kernel prior to 2.4.23, and was the method used during a recent attack on Debian's servers, according to the advisory. In that attack four Linux servers that hosted Debian's bug tracking system, mailing lists, and various Web pages were compromised.

    Security Flaw Confirmed in OpenOffice


    Security Flaw Confirmed in OpenOffice 04/13/2005 12:02 PM
    The makers of the OpenOffice.org productivity suite confirmed late Tuesday that a buffer overflow flaw does indeed exist in both the latest stable and beta versions of the software. The issue could potentially make its users vulnerable to code execution attacks.

    New Microsoft patch to fix security flaw


    New Microsoft patch to fix security flaw 09/16/2004 11:21 AM

    Kryptonite U-Lock Security Flaw


    Kryptonite U-Lock Security Flaw 09/18/2004 10:44 PM

    Security Flaw Uncovered in Trillian


    Security Flaw Uncovered in Trillian 03/25/2005 03:48 PM
    A potential security vulnerability has been discovered in Trillian, an alternative instant messaging client created by Cerulean Studios that supports AIM, ICQ, MSN and Yahoo IM networks. The flaw involves a buffer overflow that could be exploited to gain control of a Trillian user's PC.

    vBulletin Unspecified Security Flaw


    vBulletin Unspecified Security Flaw 06/13/2002 09:43 AM

    SQL security flaw persists in many web
    sites


    SQL security flaw persists in many web
    sites
    01/11/2004 01:36 AM

    Win32: Postmessage API security flaw


    Win32: Postmessage API security flaw 03/14/2003 03:35 PM
    Palan (Mar 13 2003)

    Security flaw found in Firefox


    Security flaw found in Firefox 04/10/2005 05:40 AM

    Microsoft haunted by old IE security
    flaw


    Microsoft haunted by old IE security
    flaw
    06/30/2004 12:49 PM
    IE vulnerability patched six years ago resurfaces in newer releases and could allow hackers to change content on Web sites.

    Notes and Tips: Security Flaw
    Workarounds


    Notes and Tips: Security Flaw
    Workarounds
    05/18/2004 04:19 PM
    Here are two workarounds to ameliorate the Help security flaw in Mac OS X.

    CheckPoint driven through by gung-ho
    security flaw


    CheckPoint driven through by gung-ho
    security flaw
    07/29/2004 09:45 AM
    CheckPoint Software Technologies Ltd. has issued fixes for a critical flaw in its popular virtual private networking (VPN) products that could allow a remote attacker to invade a network.

    Security Flaw Found In Trillian IM
    Client


    Security Flaw Found In Trillian IM
    Client
    03/25/2005 11:42 PM

    Security Group Warns of Linux Flaw


    Security Group Warns of Linux Flaw 01/05/2004 03:00 PM

    Grok Description matches for Mac OS X Flaw Still Unfixed, Says Security Firm
    GrokA matches for Mac OS X Flaw Still Unfixed, Says Security Firm

    Mac OS X Flaw Still Unfixed, Says Security Firm

    The following phrases have been identified by the grok system as matching this entry:

















    Also check out:


    Grok

    Ipod Porn on the
    Rise

    Brief Abstract of
    Wikipedia's
    Mesothelioma Cancer
    page

    Get first aid
    instructions in your
    cell phone

    IE is crap
    JSPWiki gains
    podcasting support

    Seeking the Best
    Battery for Digital
    Music Players
    (Reuters)

    Windows XP SP2
    Inches Closer

    Creating
    complementary
    colors?

    Wi-Fi yak farmers
    liberated by Net

    RIAA targets 493
    more unnamed
    file-sharers

    IBM gives SAN File
    System a second try

    Hitachi production
    ramp-up = cheaper
    storage

    Deutsche Telekom
    acquires US mobile
    networks

    Comcast hands MS
    five million viewers

    Drive makers ready
    5x DVD-RAM burners

    Eurofighter at risk
    of 'catastrophic
    failure'

    US plans $10bn
    computer dragnet

    Maypole::View::Mason
    Casio XFER XF-1000
    WiFi TV

    Off to CeBit
    America!

    Treo 660 Loses
    Antenna?

    A table and some
    chairs

    The 29% Nation of I
    Don't Care.

    Bush campaign
    outsources campaign
    to India

    Marvel Gets Direct
    Signing Off on Sina
    Monster's Tickle
    Fetish

    A Proxy for
    Management

    British Sky
    Broadcasting Looks
    Up

    Russia's Big Break
    Feeling Contrary?
    Move to Europe!

    Head of e-government
    unveiled

    ircd-firefox
    Appeals Court
    Rejects Microsoft
    Plea; Lindows Case
    Heads to Trial

    Microsoft Announces
    Windows for Super
    Computers

    Gmail already
    popular before
    launch

    Microsoft Talks
    Tough About Open
    Source

    Campaign to push
    Server 2003

    Microsoft Remembers
    Access With
    Conversion Kit

    mezzoblue v4
    Editor on New
    Hampshire Public
    Radio Wednesday

    Boxers or Briefs?
    Playing with Their
    Food (Reuters)

    Church Investigates
    Weeping Statues
    (Reuters)

    Online government
    gets new chief

    Venus clouds 'might
    harbour life'

    Holyrood site
    failure 'gigantic'

    Loyalists 'must end
    feud'

    F1: Silverstone wins
    British GP

    Beckham rebuffs
    critics

    W. Thomas Smith Jr.
    on Fallujah on
    National Review
    Online

    Bush Starts Out on a
    5-Week Uphill Run
    Concerning Iraq

    Najaf Shrine Is
    Damaged in Clashes

    After 4-Day Strike,
    SBC Reaches Deal
    With Employees

    Season's Twilight at
    Carnegie for Levine
    and Met Players

    what is grok?