SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> IT Workplace >> Knowledge Management

Google issues patch for desktop vulnerability

Google issues patch for desktop vulnerability

By:  Robert McMillan  On: 21 Feb 2007 For: IDG News Service (San Francisco Bureau) Creator

Security researchers have discovered a serious flaw in Google Inc.'s desktop software that could be used to wreak havoc on a victim's computer.

COMMENT ON THIS ARTICLE

Security researchers have discovered a serious flaw in Google Inc.'s desktop software that could be used to wreak havoc on a victim's computer.

The bug, which was made public Wednesday by Watchfire Corp., has now been fixed. While Google is automatically delivering a patch, Google Desktop users who want to be sure they are running the latest version of the software can download it here. Users should be running version 5.0.701.30540 or later, said Google Spokesman Barry Schnitt, via e-mail.

Google was first notified of the problem on Jan. 4, and produced its fix on Feb. 1, a Watchfire spokesman said Wednesday.

In addition to its bug fix, Google has added, "another layer of security checks to the latest version of Google Desktop to protect users from similar vulnerabilities in the future," Schnitt said. "We have received no reports that this vulnerability was exploited," he added.

Watchfire's research underscores the danger of integrating Web-based applications with the desktop, the company said in a white paper, published Wednesday.

The flaw lies in a search parameter used by Google Desktop's Advanced Search feature, which could be used to execute malicious JavaScript code, according to Watchfire.

For this attack to work, the criminal would have to first go through a number of steps, including hacking Google.com to find a cross site scripting vulnerability on the Web site -- something that has been done several times in the past year, according to Watchfire.

If successful, however, the attack would be devastating. A criminal could search for anything on the computer or even take over the victim's computer by tricking Google desktop into running malicious software stored on another computer, Watchfire claims.

COMMENT ON THIS ARTICLE


Sign up for our Newsletters












Print |  Views: 596   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Robert McMillan Robert McMillan is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Wal-Mart Web win for Q9
Wal-Mart Web win for Q9The retailer's Web site handles up to four million visitors per month and catalogues 5,000 items available in store.
Gmail zero-day flaw allows attackers to steal messages
Gmail zero-day flaw allows attackers to steal messagesAccounts on Google Inc.’s Gmail can be easily hacked, allowing any past and future e-mail messages to be forwarded to the attacker’s own in-box.
Industry puts Google through security search
Industry puts Google through security searchIn a report published Monday, researchers at Ponemon Institute will detail their findings about existing concerns among IT professionals regarding the protection of Google Desktop, the company's PC search utility, specifically within the confines of business operations
Google celebrates a decade in business
search engine mogul google inc. will celebrate its tenth anniversary on sunday sept. 7. ten years since its inception, the popular use of ‘google’ as a verb is testament to the fact that the company has established a presence in people’s everyday lives. but the mountain view, calif.-based company, started by two stanford ph.d student
VIDEO: Google exec clarifies Chrome questions
highlights from google’s mobile engineering manager alex nicolaou’s keynote speech on chrome and the chromium.org open source project at ibm’s cascon 2008 conference in richmond hill, ontario. (video runs approx. 5 minutes)

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.