Tiger vulnerability could lead to data loss
Tiger vulnerability could lead to data loss

Security hole bites Apple's Tiger

Latest Widgets handy for hackers

Tom Sanders in California

The latest version of Apple's Tiger operating system, OS X 10.4, exposes users to a vulnerability that could lead to data loss, security experts have warned.

The software includes the newly developed version 2.0 of Apple's Safari browser which is preconfigured to allow for software to be installed on a system without any user approval.

Advertisement

This software in turn could delete files, format the hard drive or change user settings to direct the browser to a certain website.

Several proof-of-concept exploits have been published on the web. Users running Tiger are strongly advised not to visit any of the sites that demonstrate how the flaw is exploited, such as Stephan.com.

Systems running Windows or older versions of OS X can open the page without any concern.

The exploit uses Widgets, small Java-based applications that run inside Tiger's Dashboard platform for applications such as the calculator and stock price tickers. Third-party developers can also develop software for the platform.

Widgets are hard to remove once installed. Dashboard does not offer any method of removal, and users will have to manually delete the files from a directory.

Users are also advised to disable the automatic installation for Safari until Apple has published a patch. An alternative is to make the directory containing the Widgets read only.

Apple released OS X 10.4 Tiger in late April. In addition to the Dashboard vulnerability, users have reported security issues with network connections.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Apple to launch client and server upgrades to Mac OS X version 10.4 tonight

Apple bares Tiger's teeth tonight

Client and server upgrades to Mac OS X 10.4 unveiled worldwide

Report: Tiger brings host of updates to Mac

Apple adds features that Windows will not have until Longhorn ships

Apple prepares to unleash Tiger OS

Mac OS X version 10.4 boasts '200 enhanced features'

Related whitepapers

Related jobs

Most watched

Summit: Views From the Valley

V3.co.uk's US office weighs in on the information overload crisis

John Chambers speaks on collaboration

Cisco boss talks up new offerings

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

Nikos Drakos

Summit: Dealing with communications overload

We ask Gartner Research director Nikos Drakos for advice on...

HP logo

HP scoops up 3Com for $2.7bn

Deal nearly doubles size of HP's networking operation

Data security

Summit video: Open Rights Group discusses data privacy

ORG's Jim Killock calls on the government to become more...

John Chambers speaks on collaboration

Cisco boss talks up new offerings

Primary Navigation