MacUpdate Weekend Sale :This weekend MacUpdate has slashed prices on Painter 12 and Painter Lite. Painter 12 retails for $429, but has been reduced by 54% to $199. Painter Lite has seen a 58% price cut from $69 to $29. Hurry, because these deals are only available until May 19th 2013.      
toggle

AAPL Stock: 433.26 ( -1.32 )

http://www.macnn.com/articles/09/06/08/safari.security.updated.v4/

Safari 4 resolves numerous security issues

updated 07:00 pm EDT, Mon June 8, 2009

 

Safari security updated V4


The new Safari 4.0, announced today at the WWDC keynote address, includes a host of security enhancements. Issues with CFNetworks have been resolved, with the program examining the content of CFNetwork files and treat them as HTML, and downloading files to the user's secure temporary direction location. CoreGraphics has also been enhanced, fixing memory corruption issues by improving bounds checking, error checking and input validation of TrueType font data.

ImageIO problems such as uninitialized pointer issues when opening PNG files have been resolved by performing additional validation of each image. V4.0 also fixes Internal Components for Unicode, improving handling of invalid byte sequences, therefore stopping attackers that attempt to bypass filters on websites.

libxml2 version 2.6.16 has numerous errors that can lead to application failure and arbitrary code negation. On Windows this is fixed by updating libxml2 to version 2.7.3, while on Mac OS X these issues are fixed by applying relevant patched.

Safari Windows has problems such as disclosure of sensitive information embedded in the browser cookies, and application reset malfunctions, which have been fixed. The Safari Windows Installer also resolves privilege issues by using a different compression method in the installer. On Mac, issues such as handling of Extended Validation certificates and unwanted disclosure of local file content have also been fixed.

WebKit resolves numerous problems by improving how the program handles byte order mark sequences, color settings, and style sheets. Other issues are also fixed by not rending Unicode ideographic spaces in the address bar, initializing the internal representation of HTML tables, allowing individual web pages to opt out of being displayed within a subframe, and ensuring event handlers are not able to directly affect an in-progress page transition. The update settles issues such as attackers attempts to duplicate embedded files with different security zones, and memory corruption caused by assigning an exception to a constant variable. Numerous other WebKit fixes have been made with the update.

Safari 4 is available for download from the Apple website for free.


by MacNN Staff

Post tools:

TAGS :

 security, software, Safari, WWDC
toggle

Comments

  1. phillymjs

    Fresh-Faced Recruit

    Joined: Jun 2000

    0

    Annoyances...

    Still doesn't leave the cursor in the Google search field if it's in there when you create a new tab.

    The Choose File... button doesn't work in Outlook Web Access, nor can I select a photo to upload to Facebook.

    Both of these issues existed in the beta and I reported them as bugs. Oh well, at least the tabs are back to normal.

  1. jpellino

    Fresh-Faced Recruit

    Joined: Oct 1999

    0

    Jpeg dragging works.

    jpeg files dragged to the finder no longer have an additional ".jpeg" suffix added to their existing suffix as they did in the beta. Anyone know if we can turn Java back on yet?

  1. testudo

    Forum Regular

    Joined: Aug 2001

    -4

    Java

    Nope, because the problem is with java, not safari. But give apple some time. 6 months is not enough time to fix a security issue.

  1. Chris Hutcheson

    Fresh-Faced Recruit

    Joined: Oct 2000

    +1

    Fckedit?

    Still seems to have problems working with fckedit in some applications - updating in Joomla seemed to resolve this, but not so much in Drupal. Seems odd, when it works (and has for years) with Firefox

  1. shawnde

    Fresh-Faced Recruit

    Joined: Apr 2008

    0

    re: Annoyances...

    Hmm, I didn't know you could access Outlook Web Access on Safari? I thought that was an ActiveX control. Have they changed it?

Login Here

Not a member of the MacNN forums? Register now for free.

 
close
Photo
toggle

Network Headlines

toggle

Most Popular

MacNN Sponsor

Recent Reviews

Brother HL-3170CDW LED Printer

We've mentioned before that we are far from a paperless society. For now, at least, there are tasks that require a piece of paper for ...

HTC One

It is hard to overstate just how critically important the HTC One is to the Taiwanese company’s fortunes. Despite its alarming decline ...

Samsung Galaxy S 4

Samsung's new flagship Android smartphone, the Galaxy S 4, faces even stiffer competition than its popular predecessor. With a five-in ...

toggle

Most Commented