On Feb 25, 2006, at 4:35 PM, Bob Jacobsen wrote: > Is there a CERT advisory? http://www.us-cert.gov/cas/techalerts/TA06-053A.html However, you can take the CERT advisory with a grain of salt. We've determined that it extends well beyond Safari to Launch Services (launchd) and the default bash shell. We've found that turning off "Open Safe Files After Download" in Safari does NOT "fix" it. We've developed a full exploit of the vulnerability that will execute outside Safari in normal workflow. Again, wanna' try it? -- Chris ------------------------- PGP Key: http://astcomm.net/~chris/PGP_Public_Key/ -------------------------