Published on Mac|Life (http://www.maclife.com)


Safari Beta A Security Risk
Created 2009-06-09 15:42

HOLIDAY BUYING GUIDE
    • 10 1337 Gifts for H4x0r World Domination
    • 10 Gifts for the Mac Switcher
    • 10 Creative Gifts for Designers

    Sponsored
SEE MORE ARTICLES

FEATURES
  • The Complete iMac History -- Bondi to Aluminum
  • New Apple Products--as Imagined by the Elite Gadget Press
  • Satire: 10 Ideas Steve Pitched to Disney
  • 50 Common Mac Problems Solved
  • From iMac to iPhone: A Video Trip Down Apple Announcement Memory Lane
SEE MORE FEATURES
TOP STORIES
  • iPhone Captures 17% of Smartphone Market
  • New Macs! Redesigned White MacBook, LED iMacs, Mac mini Refresh, and a Magic Mouse
  • 69 Awesomely Free Snow Leopard Compatible Apps
  • Fifth-Generation iPod nano
  • Screencast Video: Create 3D Photo Effects in Final Cut Pro
SEE MORE TOP STORIES
News
Safari Beta A Security Risk
Posted 06/09/2009 at 6:42:32pm | by JC Domingo
  • commentComments
  • printPrint
  • emailEmail
  • Delicious
  • Digg
  • StumbleUpon
  • Reddit
  • Slashdot
  • MacBlips

Update your Safari browser as soon as possible! According to SecureMac, if you have the older version of the browser, your computer might be in danger--both Macs and PCs. Malicious websites are known to steal files from the local systems using the Safari beta by just visiting them.

The attack occurs when an Xml eXternal Entity (XXE) is planted against the parsing of the XSL XML.

To update your Safari to the latest version, launch "Software Update" on your computer.

 

COMMENTS: 3
TAGS:  Safari, Security
  • commentComments
  • printPrint
  • emailEmail
  • Delicious
  • Digg
  • StumbleUpon
  • Reddit
  • Slashdot
  • MacBlips
COMMENTS
  • Login or register to post comments

Source URL: http://www.maclife.com/article/news/local_file_theft_though_safari

Links:
[1] http://www.maclife.com/user/jc_domingo
[2] http://www.maclife.com/article/news/local_file_theft_though_safari
[3] http://www.securemac.com/safari-xsl-xml-vulnerability.php
[4] http://scary.beasts.org/security/CESA-2009-006.html