All the latest UK technology news, reviews and analysis

Security hole bites Apple's Tiger

by Tom Sanders in California

11 May 2005

Be the first to comment

  • Tweet this

The latest version of Apple's Tiger operating system, OS X 10.4, exposes users to a vulnerability that could lead to data loss, security experts have warned.

The software includes the newly developed version 2.0 of Apple's Safari browser which is preconfigured to allow for software to be installed on a system without any user approval.

This software in turn could delete files, format the hard drive or change user settings to direct the browser to a certain website.

Several proof-of-concept exploits have been published on the web. Users running Tiger are strongly advised not to visit any of the sites that demonstrate how the flaw is exploited, such as Stephan.com.

Systems running Windows or older versions of OS X can open the page without any concern.

The exploit uses Widgets, small Java-based applications that run inside Tiger's Dashboard platform for applications such as the calculator and stock price tickers. Third-party developers can also develop software for the platform.

Widgets are hard to remove once installed. Dashboard does not offer any method of removal, and users will have to manually delete the files from a directory.

Users are also advised to disable the automatic installation for Safari until Apple has published a patch. An alternative is to make the directory containing the Widgets read only.

Apple released OS X 10.4 Tiger in late April. In addition to the Dashboard vulnerability, users have reported security issues with network connections.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Business Analyst - Telecoms

Business Analyst urgently required with a background...

Business Architect - Financial Services

We have an opportunity for an experienced Business Architect...

DBA - Unix Systems Support - Investment Management

Leading Institutional Investment Manager require an individual...

Senior Manager - IT Project Management - Fund Mgt

Leading Institutional Fund Manager require a Senior IT...

To send to more than one email address, simply separate each address with a comma.