Here are some of the notable bugs from the past week in the BugBlog:
There is a bug in Apple Safari for Mac OS X 10.3.9 that may allow cross-site scripting. According to Apple, a malicious website could serve up web archives masquerading as another site's pages. This is fixed in the Apple Security Update 2005-008. They had already fixed this bug for Mac OS X 10.4.2 in their last security update.Details of how to mount an attack against Mozilla Firefox and Netscape browsers has been posted on the Web. This attack would exploit the international domain name (IDN) bug first discussed in the BugBlog on 9/12. There are two ways to guard against this new exploit. The best would be to upgrade to Mozilla Firefox 1.0.7, which was released 9/21. If you can't upgrade right away, apply the fix discussed when this bug was announced on 9/12. See the fix details at https://addons.mozilla.org/messages/307259.html.
If you don't, and you happen on a malicious website set up to exploit this, and the bad guys may take over your computer.Installing Adobe Acrobat 7.0 in some cases may interfere with Microsoft Word. According to Microsoft, these are some actions that may not be saved: changing the workspace (toolbars, views, etc) in Word; creating a macro; changing the default font; adding a toolbar. The next time you start Word, these changes aren't saved. Another problem may be when you open Word. You will see this error message
There is insufficient memory. Word cannot display the requested ont.Continued on the next page Page 1 — Page 2








Article comments