440Forums  |  MacMusic.org  |  PcMusic.org  |  440tv  |  Zicos  |  AudioLexic
and   {key13}


Safari 3.1.1 Addresses Security Issues

TidBITS

Thursday April 17, 2008. 02:10 AM
TidBITS

Apple has released Safari 3.1.1 for Mac and Windows, a security update that fixes a vulnerability exploited in the recent Pwn2Own hacking contest at the CanSecWest conference (see "Apple Becomes First Victim in Hacking Contest," 2008-03-28). According to the security release notes for Safari 3.1.1, the update tackles the JavaScript weakness in WebKit exposed at the conference by "performing additional validation of JavaScript regular expressions" to prevent a heap buffer overflow.

A flaw where a colon character in a maliciously crafted URL could lead to a cross-site scripting attack has also been repaired. Two other fixes are specific to the Windows version of Safari: a timing issue that opened up control of the address bar and a memory corruption issue.

Safari 3.1.1 is available via Software Update or as a 39 MB download. It requires Mac OS X 10.4.11 or Mac OS X 10.5.2, or Windows XP or Vista on the PC. Copyright © 2008 Jeff Carlson. TidBITS is copyright © 2008 TidBITS Publishing Inc. If you're reading this article on a Web site other than TidBITS.com, please let us know, because if it was republished without attribution, by a commercial site, or in modified form, it violates our Creative Commons License.

READERS LIKE YOU! Support TidBITS with a contribution today!Special thanks this week to David Emery, Ken Wedding,Louise Asselstine, and Mark James Lee Ingle for their support!


 

Apple released Safari 3.1.1 Windows security update that fixes vulnerability Safari 3.1.1 Addresses Security Issues
Safari 3.1.1 Addresses Security Issues Read more at TidBITS
db.tidbits.com/article/9570?rss

 

 Related News 
Apple releases Safari 3.1.1 to address four security issues Apple releases Safari 3.1.1 to address four security issues
 AppleInsider 04/16/08 10 PM 
In addition to new features, Safari 3.1 tackles security issues In addition to new features, Safari 3.1 tackles security issues
 Mac Central 03/19/08 07 PM 
Apple Releases Safari 3.1.1, Addresses PWN2OWN Vulnerability Apple Releases Safari 3.1.1, Addresses PWN2OWN Vulnerability
 MacRumors 04/16/08 10 PM 
Sync issues after Safari 3.1 (.Mac, iPhone/iPod, etc.) Sync issues after Safari 3.1 (.Mac, iPhone/iPod, etc.)
 MacFixIt 03/24/08 06 PM 
Safari 3.1.1: more on slowness; DNS, iChat issues; crashes Safari 3.1.1: more on slowness; DNS, iChat issues; crashes
 MacFixIt 04/18/08 06 PM 
Safari 3.1: Google Reader/Gmail problems; PithHelmet fix; Sec... Safari 3.1: Google Reader/Gmail problems; PithHelmet fix; Sec...
 MacFixIt 03/20/08 06 PM 
Firefox 2.0.0.13 Fixes Two Critical Security Issues Firefox 2.0.0.13 Fixes Two Critical Security Issues
 TheMacObserver 03/28/08 09 PM 
Safari 3.1.1 Update (w/security fixes) Safari 3.1.1 Update (w/security fixes)
 AccelerateYourMac 04/16/08 09 PM 
Safari 3.1.1 improves security, stability Safari 3.1.1 improves security, stability
 Mac Central 04/16/08 09 PM 
The Safari 3.1 update and the security content within The Safari 3.1 update and the security content within
 Mac Merc 03/19/08 04 AM 
Safari 3.1.1, Firefox 2.0.0.14 fix security flaws Safari 3.1.1, Firefox 2.0.0.14 fix security flaws
 MacNN 04/17/08 01 AM 
Safari 3.1.1 gets WebKit security enhancements Safari 3.1.1 gets WebKit security enhancements
 MacFixIt 04/17/08 12 AM 
Details on Safari 3.1 Security Fixes Posted Details on Safari 3.1 Security Fixes Posted
 TheMacObserver 03/18/08 07 PM 
Apple Posts Safari 3.1.1 with Security Fixes Apple Posts Safari 3.1.1 with Security Fixes
 TheMacObserver 04/16/08 10 PM 
Mac hacked in security contest via undisclosed Safari vulnera... Mac hacked in security contest via undisclosed Safari vulnera...
 Mac Daily News 03/28/08 03 AM 
Apple Updates Safari for Mac, Windows with Security Fixess Apple Updates Safari for Mac, Windows with Security Fixess
 TheMacObserver 04/18/08 03 PM 
Security Update 2008-002 v1.1: requirement confusion, Safari ... Security Update 2008-002 v1.1: requirement confusion, Safari ...
 MacFixIt 03/27/08 07 PM 
Front Row 2.1.3: fix for language issues Front Row 2.1.3: fix for language issues
 MacFixIt 04/04/08 11 PM 
A possible fix for iCal sync issues on 'iDevices' A possible fix for iCal sync issues on 'iDevices'
 MacOsxHints 03/18/08 03 PM 
Fixes for Leopard's AirPort issues Fixes for Leopard's AirPort issues
 MacFixIt 04/21/08 10 PM 
Microsoft issues first update to Office 2008 for Mac Microsoft issues first update to Office 2008 for Mac
 AppleInsider 03/11/08 07 PM 

Search

Mac Zicos
Fri March 19, 09:19 AM
and   {key13}