Latest Comments
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"I have been the recipient of Agent.JEN.Trojan through an email suggesting a UPS parcel (including..."
by Vincent Laing | Nov 13, 2008 4:01 PM

Apple updates Safari for Windows to patch bugs

  • Email a Friend
  • Print Page
Apple updates Safari for Windows to patch bugs
By Dan Kaplan
Jun 15, 2007 10:09 AM
Tags: Apple | updates | Safari | for | Windows | to | patch | bugs
Safari version 3.0.1 corrects at least three "critical" vulnerabilities that could permit remote attackers to launch a DoS condition or execute arbitrary code, according to a FrSIRT advisory released today.

The fact that flaws were discovered hours after the beta went public is not surprising, Rob Ayoub, industry manager for research firm Frost & Sullivan, told SCMagazine.com.

"The Windows researcher community is more active and they’re more familiar with some of the fuzzing technology (used to find vulnerabilities)," he said. "It does send some message to Apple that they have to have a more solid testing procedure in place. Had this been an actual release, I think it would have been pretty disastrous."

One of the flaws is caused by an input validation error when processing URLs, another is related to a memory read error that occurs when processing malformed data. The third is caused by a race condition when processing JavaScript, according to FrSIRT.

Ayoub said users should not be turned off to Safari because of the early vulnerabilities found in the beta version.

"I think it’s a little bit overactive at this point," he said. "Vista, when they do their release candidates, there are tons of bugs."

Plus, he said he doesn’t anticipate many enterprise customers to immediately deploy Safari, so the number of affected users should be minimal.

Less than a day after the release of the beta version for Windows, billed by Apple as superior in speed and performance compared to the Internet Explorer and Mozilla's Firefox web browsers, researchers from Errata Security posted a number of bugs.

In addition, researcher Thor Larholm revealed a "fully functional command execution vulnerability, triggered without user interaction simply by visiting a website."

"I’d like to note that we found a total of six bugs in an afternoon, four DoS and two remote code execution bugs," David Maynor, Errata’s founder and CTO, said Monday on the organisation’s blog.

"We have weaponised one of those to be reliable and it’s different than what [Larholm] has found. The exploit is robust, mostly thanks to the lack of any kind of advanced security features in OS X."

Apple, though, said none of the revealed vulnerabilities apply to the Mac OS X version of Safari, according to reports.

An Apple spokesperson could not be reached for comment.

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Patch Management Whitepapers