Home >> Security >> Security Products, Practices and Infrastructure

Stop using Safari for now: Microsoft

Stop using Safari for now: Microsoft By:  Gregg Keizer On: 01 Jun 2008 For: ComputerWorld (US) Creator

Microsoft Corp. has advised Windows users not to use Safari for Web browsing until either Apple or Microsoft releases a security patch. Apple has nothing to say for now.



Email a friend   |  









Print   |   Text + / -   |  Add a Comment   |   Views: 466   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




In an unusual move, Microsoft Corp. on Friday urged Windows users not to surf with Apple Inc.'s Safari browser until one of the companies makes a patch that plugs security holes.

One security researcher noted that Microsoft's public warning -- and Apple's silence on the subject -- are typical for the two rivals and illustrate their different approaches to security.

On Friday, the Microsoft Security Response Center (MSRC) issued a security advisory for what it called a "blended threat" caused by combination of a bug in Apple's Safari Web browser and a vulnerability in how Windows XP and Windows Vista handle executable files placed on the desktop.

"Microsoft is investigating new public reports of a blended threat that allows remote code execution on all supported versions of Windows XP and Windows Vista when Apple's Safari for Windows has been installed," said the advisory.

The Safari bug Microsoft referred to is the same one disclosed two weeks ago by researcher Nitesh Dhanjani, which Apple declined to treat as a security issue, said Andrew Storms, director of security operations at nCircle Network Security Inc. "Clearly, that's what they're talking about," said Storms.

In mid-May, Dhanjani posted information about what he dubbed a "carpet bomb" attack made possible because Safari lacks an option to require a user's permission to download a file. Attackers, Dhanjani claimed, could populate a malicious site with rogue code that Safari would automatically download to the desktop.

Apple told Dhanjani that it did not consider the problem a security issue, but might fix it in a future Safari update. The next week, the anti-malware group Stopbadware.org criticized Apple for that position. "We encourage Apple to reconsider its stance and treat this as the security issue that it is," said the group in a statement May 19.

Then on Friday, Microsoft also fingered Safari as a problem. "Restrict use of Safari as a Web browser until an appropriate update is available from Microsoft and/or Apple," the company told users in the advisory.

But Microsoft also admitted that a successful attack would require not only leveraging the Safari bug, but also exploiting a vulnerability in its own software. "A combination of the default download location in Safari and how the Windows desktop handles executables creates a blended threat in which files may be downloaded to a user's machine without prompting, allowing them to be executed," said Microsoft.


Sign up for our Newsletters
Tags: Windows, Storms,
Gregg Keizer Gregg Keizer is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Articles

Related Blogs

Comments (1)

Mr.
6/6/2008 12:00:00 AMThis is a bug only because Windows does not handle such situations. Anyone writing for Windows learns quickly that the OS does precious little in the name of protection. The applications need to take care. I don't blame Apple at all for their stand. MS needs to fix their software otherwise ALL other vendors will continue to need to fix theirs. I shouldn't have to be in my secure home and still have to lock my wallet additionally.
You are currently not logged in: Register | Login

You must be logged in to submit a comment.