AfterDawn: Tech news

Apple updates Safari to fix security problems

Written by James Delahunty @ 17 Apr 2008 12:21 User comments (1)

Apple updates Safari to fix security problems Apple Inc. has released version 3.1.1 of the Safari web browser to address several serious security problems. One of the vulnerabilities that has been fixed was widely publicized after being used to compromise a MacBook Air during a security conference. The update is available for both Mac and PC at about 39MB. It is highly recommended for all Safari users to ensure the security of their systems.
In total, four security bugs have been fixed by Apple. The aforementioned publicized security bug used to compromise a MacBook Air laptop at last month's CanSecWest security conference won Charlie Miller a $10,000 prize. The bugs also included a a heap buffer overflow present the browser's WebKit framework for handling JavaScript.



A second issue in the WebKit framework was also addressed. It involved WebKit's handling of URLs that contain a colon character in the host name, which could have been exploited by a malicious user to create a crafted URL to lead a cross-site scripting attack. Two other issues allowed malicious users to manipulate the contents of the address bar, or to execute arbitrary code.


Get regular news updates from AfterDawn.com by subscribing to our RSS feeds using the Subscribe button below. If you have been living in a cave for a few years now and don't know how to use RSS feeds, then Click Here to read a Guide on how to use RSS (and other) feeds.

Previous Next  

1 user comment

118.4.2008 10:51

*Gasp* Security Flaws in my perfect OS from Apple.

Comments have been disabled for this article.

Latest news

VLC hits milestone: over 5 billion downloads VLC hits milestone: over 5 billion downloads (16 Mar 2024 4:31)
VLC Media Player, the versatile video-software powerhouse, has achieved a remarkable feat: it has been downloaded over 5 billion times.
2 user comments
Sideloading apps to Android gets easier, as Google settles its lawsuit Sideloading apps to Android gets easier, as Google settles its lawsuit (19 Dec 2023 11:09)
Google settled its lawsuit in September 2023, and one of the settlement terms was that the way applications are installed on Android from outside the Google Play Store must become simpler. In the future, installing APK files will be easier.
8 user comments
Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets (06 Jun 2023 9:19)
Roomba Combo j7+ is the very first Roomba model to combine robot vacuum with mopping features. And Roomba Combo j7+ does all that with a very clever trick, which tackles the problem with mopping and carpets. But is it any good? We found out.
Neato, the robot vacuum company, ends its operations Neato, the robot vacuum company, ends its operations (02 May 2023 3:38)
Neato Robotics has ceased its operations. American robot vacuum pioneer founded in 2005 has finally called it quits and company will cease its operations and sales. Only a skeleton crew will remain who will keep the servers running until 2028.
5 user comments
How to Send Messages to Yourself on WhatsApp How to Send Messages to Yourself on WhatsApp (20 Mar 2023 1:25)
The world's most popular messaging platform, Meta-owned WhatsApp has enabled sending messages to yourself. While at first, this might seem like an odd feature, it can be very useful in a lot of situations. ....
18 user comments

News archive