Apple Plugs Windows Safari Security Holes

By the Betanews Staff | Published June 14, 2007, 2:19 PM

Just days after its beta release of Safari 3 for Windows became a zero-day nightmare with a number of exploitable vulnerabilities, Apple has rushed out version 3.01 to fix three security flaws. The problems only affect Windows, not the Mac OS X release.

The 3.01 update patches a bug that could lead to Safari running arbitrary commands via CMD.EXE, a denial of service crash due to memory corruption, and a flaw that could lead to a cross-site scripting attack. Windows XP and Vista users can download Safari 3.01 from FileForum.

Comments

hmm, patched in 3 days...I'm impressed.

Score: 0

|

How about the intermittent crash when you change to a "multi-firewalled" proxy?

I experience this a lot. Especially a proxy that requires user authentication. I hope Safari developers will look into this.

Score: 0

|

Wow, I had no idea that Betanews had so many damn ads until I visited in Safari.

Back to Firefox for me until they make an add-on that blocks ads.

I'm typing this in Safari right now and I count 4 ads on the page. With Firefox I see ZERO ads.

Score: 0

|

What business do you have reading and obviously ad supported website and striping out the ads. If you are going to have that little class you might want to keep it to yourself. Or maybe you can offer to pay the website for the content some other way. These people have to work for a living to feed their families just like everyone else, but you want them to provide you with information for free. What do you do for a living? maybe you should give me something for free. Why don't you come mow my lawn or clean my toilets. Freeloading jackass. Was that a personal attack or a factual criticism? I’ll leave it up to the moderator to decide.

Score: 0

|

lol.... well spoken.

Score: 0

|

The only personal attack is coming from you.

As for people browsing this website with ad-blocking technology, if you think most people who read this site don't have that enabled, you're delusional. Don't bash people for being honest.

Score: 0

|

Good job on patching the 3 holes, but they have more work to do. They may have taken a big perception hit too.

Score: 0

|

Nah, only geeks are paying attention at this stage. :-)

Score: 0

|

I see they've still not fixed the rather nasty font bug yet.

Score: 0

|

Just replace the Lucida fonts in your program files folder with the ones from your system fonts folder and you'll be good.

Score: 0

|

That was quick! Good job Apple!

Score: 0

|

I'm sure there's going to be all sorts of interesting posts on this topic, but nevertheless, it's good to see Apple patch these flaws so quickly. Isn't that what beta testing is all about? Yes I know they shot their mouths off about how secure Safari is, but hey it's their first attempt at a browser for Windows.

Score: 0

|

"The problems only affect Windows, not the Mac OS X release."

Gee, I would have never guessed. LATN!

Score: 0

|

really... cause thats not what i heard.

"These bugs have been verified in the current PRODUCTION copy on OSX."
http://erratasec.blogspo...07/06/niiiice.html";

Score: 0

|

One wonders why that URL no longer exists!

Score: 0

|

its there, just an extra accidental quote at the end:
http://erratasec.blogspot.com/2007/06/niiiice.html

Score: 0

|

Yeah, the thread exists, but it stopped the other evening at 6 pm.

Maynor claims the bugs affect the OS X version too, then blames the lack of security in OS X.

But if the bugs are in the Windows version too, then how could they have anything to do with OS X? Great logic.

Personally I don't believe him. The MOAB didn't uncover any such easily found Safari bugs.

Score: 0

|

Just watch your posts my friend. Last time I got blasted with personal attacks by the Apple followers when I showed them that link (as if I wrote it), when the story was first announced. You have been warned :) I have a feeling the same thing will happen now. This is the only reason I will never use Mac OS X or recommend it to anyone - Arrogant community

Score: 0

|

hey IT'S A FUKING BETA VERSION!!! g**d*** PEOPLE

Score: 0

|

Kudos to Apple for reacting promptly. I only hope they don't take another dig at PC using this incident (like they always do).

Score: 0

|

They probebly will...

Score: 0

|

Yea, doesn't the John Hodgeman character get to say "How 'bout that total sukfest called Safari, there, mr. apple giblets?"

Hahahahahaha

Score: 0

|

Nokia: Android? Are you crazy?

Rumors about new Android devices abound, but Nokia squashes this one.

What's Now: Drenched with 'Purple Ra1n,' iPhone users caught eating 'redsn0w'

Plus: Symantec and McAfee go to war, and what's LucasArts building in its top-secret, moon-shaped orbital facility?

Can Linux do BitLocker better than Windows 7?

Betanews kicks off a new series with a look at how the Linux operating system's FDE stacks up against BitLocker, the Windows feature that today commands a $120 premium.

Firefox 3.5: The need for speed

This has been the big payoff week for Mozilla's developers, who worked overtime to squeeze out the last drop of performance from their new JavaScript engine.

'GeoHot' gets a shower, cleans up nice, reveals new iPhone 3G S jailbreak

Either puberty has been very kind to the author of the new 'Purple Ra1n' jailbreak tool, or George Hotz may also have some adequate Photoshop skills.

Symantec goes live with Norton 2010 betas

Norton Internet Security and Norton Antivirus 2010 are now available for testing.

IE8 WSUS update push to begin August 25

After months of availability to users willing to seek it out, Internet Explorer 8 will be rolled into Windows Server...

In New York, online booze loses a Circuit Court decision

Court worried about gangster influence if liquor purchased directly.

Geeks vs. journalists: A tale of two worldviews

Recovery with Angela Gunn Why geeks think most mainstream journalism is flaky, and why the mainstream thinks geeks are trying to kill them. (They're both right.)

Fire in downtown Seattle data center knocks out businesses, online services

Small fire has global impact with payment centers, city services down.

What's Next: Obama gives 'Einstein' the go-ahead, while China gives 'Green Dam' a thumbs-down

Plus: If you put up a Web site and name it after you and you're a federal judge, you might not want a bunch of weird nudity hanging around on it.

Hybrid satellite cell phones aren't far off

The first satellite in Terrestar's hybrid cellular/satellite phone network has been launched.

VirtualDub 1.9.3 Experimental

July 6 - 1:28 PM ET

CDBurnerXP Pro 4.2.4.1420

July 6 - 1:07 PM ET

AbiWord for Windows 2.7.6 Beta

July 6 - 12:46 PM ET

Notepad++ 5.4.4

July 6 - 12:25 PM ET

KeePass Password Safe (v2.x) 2.0.8

July 6 - 12:04 PM ET

ReactOS 0.3.10

July 6 - 11:43 AM ET

Tux Paint for Windows 0.9.21

July 6 - 11:22 AM ET