Safari, IE Bugs Pose Serious Blended Threat to Windows Users

<a href="http://www.infoworld.com/article/08/06/02/Safari-flaw-worse-than-first-thought_1.html">InfoWorld</a>

Jim Manico, OWASP Global Board Member

June 2, 2008

1 Min Read

Microsoft is warning Windows Vista and XP users of a blended threat involving Apple's Safari browser and its Internet Explorer browser.Turns out, if a Safari bug disclosed mid-May is exploited with a second unpatched bug in Microsoft's Internet Explorer browser, then hackers are able to run unauthorized software on a victim's computer. Separately, the bugs are considered moderate; in tandem, they are deemed critical and enable remote execution.

"At the present time, Microsoft is unaware of any attacks attempting to exploit this blended threat. Upon completion of this investigation, Microsoft will take the appropriate measures to protect our customers," according to a security advisory on Microsoft's Web site. "This may include providing a solution through a service pack, the monthly update process, or an out-of-cycle security update, depending on customers' needs."InfoWorld

Read more about:

2008

About the Author(s)

Jim Manico

OWASP Global Board Member

Jim Manico is a Global Board Member for the OWASP foundation where he helps drive the strategic vision for the organization. OWASP's mission is to make software security visible, so that individuals and organizations worldwide can make informed decisions about true software security risks. OWASP's AppSecUSA<https://2015.appsecusa.org/c/> conferences represent the nonprofit's largest outreach efforts to advance its mission of spreading security knowledge, for more information and to register, see here<https://2015.appsecusa.org/c/?page_id=534>. Jim is also the founder of Manicode Security where he trains software developers on secure coding and security engineering. He has a 18 year history building software as a developer and architect. Jim is a frequent speaker on secure software practices and is a member of the JavaOne rockstar speaker community. He is the author of Iron-Clad Java: Building Secure Web Applications<http://www.amazon.com/Iron-Clad-Java-Building-Secure-Applications/dp/0071835881> from McGraw-Hill and founder of Brakeman Pro. Investor/Advisor for Signal Sciences.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights