NEWS

Apple, Mozilla, and Sophos - The BugBlog Report 5/15/06

Written by Bruce Kratofil
Published May 15, 2006
Part of BugBlog

Apple's Security Update 2006-003 squashes a bug in LaunchServices for Mac OS X 10.4.6 Client and Server. According to Apple, a long file name extension may interfere with Download Validation. This may let an attacker design a file with unsafe content, but appears to be safe to Mac OS X 10.4, which will then let an application, such as Safari, open the file. The security update does a better job of checking long file name extensions. Security Update 2006-003 includes many more fixes for bugs that may allow an attacker to run hostile code on your computer.

There is a bug in Mozilla Firefox 1.5.0.3, according to the Sans Internet Storm Center. A web page can be designed in a way to trick the function that automatically opens your email program when you click on a mailto: link, so that one click may rapidly open up 100 email windows on your computer, crashing it in a denial of service attack. It does not appear that attackers can use this to run code on your system.

A bug has been found in the Sophos line of anti-virus products. The bug is in the way that Microsoft Cabinet (.CAB) files are unpacked. An attacker may be able to construct a .CAB file in a way that lets them sneak their code onto your computer and then execute it. Sophos has updates available. See the chart at Sophos for information on each product. It does not appear that this flaw has been exploited yet, although now the bad guys know where to look.

Bruce Kratofil blogs on bugs and other things that can go wrong with your computer at The BugBlog, and writes about computers and economics at BJK Research
Keep reading for information and comments on this article, and add some feedback of your own!
Apple, Mozilla, and Sophos - The BugBlog Report 5/15/06
Published: May 15, 2006
Type: News
Section: Sci/Tech
Filed Under: Sci/Tech: Computers, Sci/Tech: Internet, Sci/Tech: Software
Part of a feature: BugBlog
Writer: Bruce Kratofil
Bruce Kratofil's BC Writer page
Bruce Kratofil's personal site
Spread the Word
Like this article?
Email this
Submit to del.icio.us Save to del.icio.us
RSS Feeds
All RSS Feeds (240+)
Comments on this article
Articles in this series
BC articles by Bruce Kratofil
Sci/Tech: Computers
Sci/Tech: Internet
Sci/Tech: Software
All Sci/Tech Articles
Bruce Kratofil's personal weblog
All News articles
All BC articles
All BC Comments

Comments

Want comments emailed to you? No spam, promise! Address:

Add your comment, speak your mind

(Or ping: http://blogcritics.org/mt/tb/47767)

Personal attacks are not allowed. Please read our comment policy.





Remember Name/URL?

Please preview your comment!

Fresh
Articles
Fresh
Comments