Tiger vulnerability could lead to data loss
Tiger vulnerability could lead to data loss

Security hole bites Apple's Tiger

Latest Widgets handy for hackers

Written by Tom Sanders in California

The latest version of Apple's Tiger operating system, OS X 10.4, exposes users to a vulnerability that could lead to data loss, security experts have warned.

The software includes the newly developed version 2.0 of Apple's Safari browser which is preconfigured to allow for software to be installed on a system without any user approval.

Advertisement

This software in turn could delete files, format the hard drive or change user settings to direct the browser to a certain website.

Several proof-of-concept exploits have been published on the web. Users running Tiger are strongly advised not to visit any of the sites that demonstrate how the flaw is exploited, such as Stephan.com.

Systems running Windows or older versions of OS X can open the page without any concern.

The exploit uses Widgets, small Java-based applications that run inside Tiger's Dashboard platform for applications such as the calculator and stock price tickers. Third-party developers can also develop software for the platform.

Widgets are hard to remove once installed. Dashboard does not offer any method of removal, and users will have to manually delete the files from a directory.

Users are also advised to disable the automatic installation for Safari until Apple has published a patch. An alternative is to make the directory containing the Widgets read only.

Apple released OS X 10.4 Tiger in late April. In addition to the Dashboard vulnerability, users have reported security issues with network connections.

Tags:

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Shaun Nichols and Iain Thomson

03 Oct 2008

6.49 MBPodcast Special: Views from the Valley More...

Podcast image

02 Oct 2008

14.35 MBComputing podcast - Next-generation broadband Britain; and we report from Gartner's IT security summit More...

Shaun Nichols and Iain Thomson

26 Sep 2008

3.43 MBPodcast Special: Views from the Valley More...

Poll

Google Android

Google Android

Are you intending to try out a Google Android mobile phone?

Previous poll results

Spotlight

T-Mobile

T-Mobile loses 17 million customer details

Deutsche Telekom unit at centre of new scandal   More...

BusinessObjects XI 3.1

SAP unveils new BI integration with Oracle

BusinessObjects XI 3.1 offers increased integration, speed and scalability   More...

ISSE 2008

Distributed collaboration tools add to risk burden

Business and legal teams must act now, says Microsoft   More...

BlackBerry Storm

RIM unveils BlackBerry Storm touch phone

Latest handset adds feedback mechanism to touch screen   More...

Primary Navigation