Apple patches two critical Safari bugs

By Matthew Broersma, ZDNet UK
Friday, July 10, 2009 10:46 AM

Apple has released an update for its Safari 4 Web browser, which fixes two serious vulnerabilities that could allow an attacker to conduct a cross-site scripting attack or take over a user's system.

The update, Safari 4.0.2, was made available on Wednesday. Independent security vendor Secunia gave the flaws addressed by the update a "highly critical" ranking. The bugs affect both the Windows and Mac versions of Safari.

Both of the flaws affect WebKit, the open source layout engine used in Safari. The more serious of the two bugs is a memory corruption problem in WebKit's handling of numeric character references, which could allow an attacker to execute malicious code on a user's system via a specially crafted website, Apple said in an advisory. The vulnerability could also allow an intruder to shut down the application.

The second bug is an input validation problem with WebKit's handling of parent and top objects. This vulnerability could allow a Web site to execute HTML and scripting code in the security context of another Web site, in what is known as a cross-site scripting attack. "This update addresses the issue through improved handling of parent and top objects," Apple said in the advisory.

The bugs are fixed in update 4.0.2, which can be downloaded from Apple Downloads or via Mac OS X's built-in Software Update mechanism, according to the company.

Safari 4 was brought out of beta last month, with new features such as the accelerated Nitro JavaScript engine.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

3 lessons a CIO can learn from Windows 7

Tech Management

Microsoft's missteps with Vista, and attempts at redemption with Windows 7, offers firms valuable lessons in IT, be it in rolling out a new corporate application or delivering millions of copies of a new OS.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web