troubleshooting/tutorials/security

06/14/2007, 9:20am, EDT

Thursday, June 14th

Safari 3.01 for Windows fixes security flaws

Apple has released Safari 3.01 for Windows, an update to the public beta that was announced earlier this week. The browser, now available for Windows XP and Vista, is based on the same WebKit foundation as the Mac and iPhone version. Although specific details of the update were not provided via Apple's security website, the release comes on the heels of criticism of Apple by researchers who claim to have found more than 18 security flaws in the Safari browser within a few days of its release.

The updated Safari download is not specifically noted on Apple's website, but it is available via the Apple Software update on Windows or via Apple's website. According to Macworld, the security improvements in Safari Beta 3.0.1 include a correction for a "command injection vulnerability," remedied with additional processing and validation of URLs that could otherwise lead to an unexpected termination of the browser; an out-of-bounds memory read issue; and a race condition that can allow cross-site scripting using a JavaSscript exploit. The report said that these flaws do not affect the Mac version.


Filed under: troubleshooting

, , 6comments, del.icio.us, slashdot, digg, buzz


6 comments
Reader Reactions (Please use <i></i> for italic text)

subscribe to comments
for this article




Expand All   Global Settings
maybe now...
0
06/14, 9:59am, EDT
...Maynor will play nice. Apple fixed these in near-record time. Perhaps he, and the MOAB couple can stop throwing tantrums and be more professional. We'll see.

I'm sick of self-proclaimed security experts acting like skateboarders who just went thru your plate glass window and then shrug and tell you it was your fault for not having safety glass.

Fresh-Faced Recruit
Joined Oct 1999
User is offline
dws
Maynor...
0
06/14, 10:29am, EDT
...will never play nice; especially now that he is getting so much attention from his claim that he intends to hack the iPhone.
Forum Regular
Joined Apr 2001
User is offline
Re: maynor
0
06/14, 11:32am, EDT
BTW, they announced the bugs but did not disclose them. Not sure what isn't 'playing nice' in that regard.

And if it was anyone else, you wouldn't be able to wait for someone to hack it so you could add your own software and the like.
Fresh-Faced Recruit
Joined Aug 2001
User is offline
re: maybe now
0
06/14, 11:51am, EDT
While a bit sensationalistic, a security firm should be announcing but not disclosing bugs (except to Apple).
Professional Poster
Joined Sep 1999
User is offline
"security firms"...
0
06/14, 4:07pm, EDT
are often just the guy from the SouthPark WoW episode.
Fresh-Faced Recruit
Joined Aug 2001
User is offline
its all about the 'ttude
0
06/15, 7:01am, EDT
jpellino: "I'm sick of self-proclaimed security experts acting like skateboarders who just went thru your plate glass window and then shrug and tell you it was your fault for not having safety glass."

Oh yeah, you nailed it. It's all about the 'ttude . . . and I'm sick of him and his lot too.
Fresh-Faced Recruit
Joined May 2002
User is offline
Your Comments

In order to post comments: If you are a registered member, please login with your MacNN Forums username and password otherwise please uncheck the checkbox below.


Registered Member?
macnn forums login:

macnn forums password:

Not a member of the MacNN forums? Register now for free.

RSS Feeds

Have the latest content delivered to your desktop via RSS. Use the links below to get access to a specific blog, news, or reviews feed.



  MacNN -all

  MacNN Reviews

  MacNN Podcasts

  iPodNN

  Electronista

  Left Lane News
Turn your laptop into CASH: Sell us your used laptop. Working or not. Get money FAST. Instant online quote. Shipping is FREE.

Check Out the VIERA from Panasonic!: Enter a New Visual Era with Panasonic VIERA HDTVs. An Enhanced Experience.

Buy from The Apple Store, iTunes.com, Amazon.com, TechDepot, OfficeDepot, Computers4Sure, or donate.