Apple
Vulnerabilities range from cross-site scripting to remote code execution
R E L A T E D   C O N T E N T
ADVERTISEMENT

Apple patches critical Safari holes

Four flaws addressed in latest update

Shaun Nichols in California, vnunet.com 17 Apr 2008
ADVERTISEMENT

Apple has patched four security vulnerabilities in Safari affecting the Mac OS X and Windows versions of the web browser.

The vulnerabilities range from cross-site scripting to remote code execution.

For Windows XP and Vista users, the update addresses four flaws. Two of the vulnerabilities, a memory overflow error in the browser itself and a buffer overflow in the JavaScript component, could be exploited by an attacker to remotely install and execute malware on a target system.

Another flaw in the browser could allow for a URL to be displayed without the page itself being loaded. Apple warned that this could be exploited by an attacker to spoof legitimate sites by displaying normal URLs with forged web pages.

The fourth vulnerability is a flaw in the browser's WebKit component. An attacker could use a malformed URL to exploit the vulnerability and perform a cross-site scripting attack.

Mac users will receive updates for just two of the four flaws. Apple patched the JavaScript remote code execution flaw as well as the cross-site scripting vulnerability in the OS X version of the Safari patch.

Users can download the Safari update through Apple's Software Update application or from the company's Safari download site.

See also:

Apple iPhoneClearing out old stock for the anticipated 3G model?  16 Apr 2008
Apple iPhoneApple's mobile browser flawed, claims security firm  16 Apr 2008
TescoEvery hit'll help  15 Apr 2008
Apple iPhoneFlaw discovered in WPS used by iPhone and iPod Touch  15 Apr 2008

All Bugs & Fixes
Tags: Apple, Safari, Software

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
London, United Kingdom | MI5
Finance and Procurement Business Analyst, London, From £30,192 depending on skills and experience (pay award pending) As part of MI5's support team for the Oracle eBusiness Suite, you'll be supporting colleagues as they protect the ... more >
London, United Kingdom | Feltham City Learning Centre
ICT Systems Administrator - Feltham City Learning Centre - £23,097 - £24,528 A full time ICT Systems Administrator to work in the Feltham City Learning Centre. This role requires a broad range of ICT skills ... more >
Milton Keynes, Buckinghamshire, United Kingdom | EDS
About EDS EDS provides a broad portfolio of business and technology solutions to help its clients worldwide improve their business performance. EDS' core portfolio comprises information-technology and business process outsourcing services, as well as information-technology ... more >
London, United Kingdom | MI5
Business Intelligence Specialists - Competitive Salary + Excellent Benefits - London   Getting the best out of technology is critical to helping us protect the UK. Join MI5 and use your skills and experience to ... more >
More job opportunities