Apple posts Java, Safari for Windows updates
updated 05:15 pm EST, Thu February 12, 2009
Java, Safari updates
Apple has released three web-related software updates, distributing them through Software Update and its support website. The first two fix the Mac OS X 10.5 and 10.4 distributions of Java, which are said to have multiple security vulnerabilities in their Web Start and Plug-In components. Of these the most serious is said to allow elevated privileges for untrusted apps and applets, which can be embedded into malicious websites to run arbitrary code attacks.
Windows users can meanwhile download Safari 3.2.2. The browser has been patched to solve input validation problems with feed URLs; these could be used to run arbitrary JavaScript within a PC's local security zone. Apple comments that the issue does not appear in the Mac version of Safari, which has addressed the vulnerability with Security Update 2009-001.


