Apple patches DLL hijacking bug in Safari
Apple yesterday patched three vulnerabilities in Safari, including one in the Windows version that quashed a bug Microsoft said individual developers had to fix themselves.
Apple and Mozilla are the only major browser makers who have patched what most researchers have called "DLL load hijacking." In the updates to Safari 5.0.2 and Safari 4.1.2, Apple addressed a problem shared by scores of Windows applications that can be exploited by duping users into downloading innocent files.
Last month, HD Moore, chief security officer at Rapid7 and the creator of the open-source Metasploit hacking toolkit, announced that several dozen Windows programs were flawed because they improperly loaded code libraries -- dubbed "dynamic-link libraries," or "DLLs" -- and so gave hackers a way to commandeer a PC by tricking the application into calling on a malicious DLL.
