Showing posts with label Safari. Show all posts
Showing posts with label Safari. Show all posts

Thursday, May 10, 2012

Safari Update Released

Apple has released a new version of their Safari web browsers. Version 5.1.7 contains fixes to four security vulnerabilities. Some of these may lead to an unexpected application termination or allow an attacker to execute arbitrary code in affected system.

Affected are Safari versions earlier than 5.1.7. Users of vulnerable Safari versions can get the latest version here.

More information of the security content of 5.1.7 can be read here.

Tuesday, March 13, 2012

New Version Of Safari Released

Apple has released a new version of their Safari web browsers. The version contains fixes to a big bunch of security vulnerabilities. These vulnerabilities may lead to an unexpected application termination or allow an attacker to execute arbitrary code in affected system.

Affected are Safari versions earlier than 5.1.4. Users of vulnerable Safari versions can get the latest version here.

More information of the security content of 5.1.4 can be read here.

Thursday, October 13, 2011

Safari Update Available

Apple has released new version of their Safari web browser. The new version contains fixes to 23 different vulnerabilities. Some of these vulnerabilities may lead to an unexpected application termination or allow an attacker to execute arbitrary code in affected system.

Affected are Safari versions earlier than 5.1.1. Users of vulnerable Safari versions can get the latest version here.

More information of security content of 5.1.1 version can be read here.

Friday, July 22, 2011

New Versions Of Safari Released

Apple has released new versions of their Safari web browsers. The new versions contain fixes to 58 different vulnerabilities. These vulnerabilities may lead to an unexpected application termination or allow an attacker to execute arbitrary code in affected system.

Affected are Safari versions earlier than 5.1 or 5.0.6. Users of vulnerable Safari versions can get the latest version here.

Adobe warns that Safari 5.1 will break part of Adobe Acrobat and Adobe Reader Safari plugin functionality. More about this in Adobe blog post.

More information of security content of 5.1 and 5.0.6 versions can be read here.

Friday, April 15, 2011

Patched Version of Safari Released

Apple has released a new versions of their Safari web browser. Version 5.0.5 contains fixes to two WebKit (=browser engine in Safari) vulnerabilities. These may lead to an unexpected application termination or allow an attacker to execute arbitrary code in affected system.

Affected are Safari versions earlier than 5.0.5. Users of vulnerable Safari versions can get the latest version here.

More information of security content of 5.0.5 version can be read here.

Thursday, March 10, 2011

Safari 5.0.4 Available

Apple has released a new versions of their Safari web browser. Version 5.0.4 contains fixes to several vulnerabilities. These may lead to an unexpected application termination or allow an attacker to execute arbitrary code in affected system.

Affected are Safari versions earlier than 5.0.4. Users of vulnerable Safari versions can get the latest version here.

More information of security content of 5.0.4 version can be read here.

Saturday, November 20, 2010

Safari Security Updates Available

Apple has released new versions of their Safari web browsers. The new versions contain fixes to 27 different vulnerabilities. These may lead to an unexpected application termination or allow an attacker to execute arbitrary code in affected system.

Affected are Safari versions earlier than 5.0.3 or 4.1.3. Users of vulnerable Safari versions can get the latest version here.

More information of security content of 5.0.3 and 4.1.3 versions can be read here.

Wednesday, September 8, 2010

Security Updates For Safari

Apple has released new versions of their Safari web browsers. The new versions contain fixes to three different vulnerabilities. These may lead to an unexpected application termination or allow an attacker to execute arbitrary code in affected system.

Affected are Safari versions earlier than 5.0.2 or 4.1.2. Users of vulnerable Safari versions can get the latest version here.

More information of security content of 5.0.2 and 4.1.2 versions can be read here.

Thursday, July 29, 2010

Vulnerability Fix For Safari

Apple has released new versions of their Safari web browsers. The new versions contain fixes to 15 different vulnerabilities. Some of these may allow an attacker to execute arbitrary code in affected system.

Affected are Safari versions earlier than 5.0.1 or 4.1.1. Users of vulnerable Safari versions can get the latest version here.

More information of security content of 5.0.1 and 4.1.1 versions can be read here.

Tuesday, June 8, 2010

Apple Fixes Safari Vulnerabilities

Apple has released new versions of their Safari web browsers. The new versions contain fixes to 48 different vulnerabilities. Some of these may allow an attacker to execute arbitrary code in affected system.

Affected are Safari versions earlier than 5.0 or 4.1. Users of vulnerable Safari versions can get the latest version here.

More information of security content of 5.0 and 4.1 versions can be read here.

Friday, May 14, 2010

Mozilla Plugin Checker To Check Other Browsers' Plugins Too

Last fall Mozilla made available a website that Firefox users could use to check if their browser plugins were outdated. Now Mozilla has extended the plugin check to other browsers too. At the moment, supported are Safari 4, Chrome 4 and Opera 10.5. Support for the most popular, but not for all yet, plugins of Internet Explorer 7 and 8 is included too.

More information in Mozilla blog.

Saturday, March 13, 2010

Safari 4.0.5 Fixes A Bunch of Vulnerabilities

Apple has released a new version of their Safari web browser. Version 4.0.5 contains fixes to 16 security vulnerabilities.

Safari users can get fresh copy here.

More information about the security content of Safari 4.0.5 can be read here.

Thursday, November 12, 2009

Safari 4.0.4 Released

Apple has released version 4.0.4 of their Safari web browser. New version fixes six vulnerabilities:


*ColorSync
CVE-ID: CVE-2009-2804
Available for: Windows 7, Vista, XP
Impact: Viewing a maliciously crafted image with an embedded color profile may lead to an unexpected application termination or arbitrary code execution
Description: An integer overflow exists in the handling of images with an embedded color profile, which may lead to a heap buffer overflow. Opening a maliciously crafted image with an embedded color profile may lead to an unexpected application termination or arbitrary code execution. The isssue is addressed by performing additional validation of color profiles. This issue does not affect Mac OS X v10.6 systems. The issue has already been addressed in Security Update 2009-005 for Mac OS X 10.5.8 systems. Credit: Apple.

*libxml
CVE-ID: CVE-2009-2414, CVE-2009-2416
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11,
Windows 7, Vista, XP
Impact: Parsing maliciously crafted XML content may lead to an
unexpected application termination
Description: Multiple use-after-free issues exist in libxml2, the most serious of which may lead to an unxexpected application termination. This update addresses the issues through improved memory handling. The issues have already been addressed in Mac OS X 10.6.2, and in Security Update 2009-006 for Mac OS X 10.5.8 systems.

*Safari
CVE-ID: CVE-2009-2842
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.8, Mac OS X Server v10.5.8, Mac OS X v10.6.1 and v10.6.2, Mac OS X Server v10.6.1 and v10.6.2, Windows 7, Vista, XP
Impact: Using shortcut menu options within a maliciously crafted website may lead to the disclosure of local information Description: An issue exists in Safari's handling of navigations initiated via the "Open Image in New Tab", "Open Image in New Window", or "Open Link in New Tab" shortcut menu options. Using these options within a maliciously crafted website could load a local HTML file, leading to the disclosure of sensitive information. The issue is addressed by disabling the listed shortcut menu options when the target of a link is a local file.

*WebKit
CVE-ID: CVE-2009-2816
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.8, Mac OS X Server v10.5.8, Mac OS X v10.6.1 and v10.6.2, Mac OS X Server v10.6.1 and v10.6.2, Windows 7, Vista, XP
Impact: Visiting a maliciously crafted website may result in unexpected actions on other websites
Description: An issue exists in WebKit's implementation of Cross-Origin Resource Sharing. Before allowing a page from one origin to access a resource in another origin, WebKit sends a preflight request to the latter server for access to the resource. WebKit includes custom HTTP headers specified by the requesting page in the preflight request. This can facilitate cross-site request forgery. This issue is addressed by removing custom HTTP headers from preflight requests.
Credit: Apple.

*WebKit
CVE-ID: CVE-2009-3384
Available for: Windows 7, Vista, XP
Impact: Accessing a maliciously crafted FTP server could result in an unexpected application termination, information disclosure, or arbitrary code execution
Description: Multiple vulnerabilities exist in WebKit's handling of FTP directory listings. Accessing a maliciously crafted FTP server may lead to information disclosure, unexpected application termination, or execution of arbitrary code. This update addresses the issues through improved parsing of FTP directory listings. These
issues do not affect Safari on Mac OS X systems. Credit to Michal Zalewski of Google Inc. for reporting these issues.

*WebKit
CVE-ID: CVE-2009-2841
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.8, Mac OS X Server v10.5.8, Mac OS X v10.6.1 and v10.6.2, Mac OS X Server v10.6.1 and v10.6.2
Impact: Mail may load remote audio and video content when remote image loading is disabled
Description: When WebKit encounters an HTML 5 Media Element pointing to an external resource, it does not issue a resource load callback to determine if the resource should be loaded. This may result in undesired requests to remote servers. As an example, the sender of an HTML-formatted email message could use this to determine that the message was read. This issue is addressed by generating resource load callbacks when WebKit encounters an HTML 5 Media Element. This issue does not affect Safari on Windows systems.



New version can be downloaded here.

Wednesday, August 12, 2009

Safari 4.0.3 Released

Apple has released version 4.0.3 of its Safari web browser. New version fixes six vulnerabilities:
-CoreGraphics
CVE-ID: CVE-2009-2468
Available for: Windows XP and Vista
Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution
Description: A heap buffer overflow exists in the drawing of long text strings. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue through improved bounds checking. Credit to Will Drewry of Google Inc for reporting this issue.

-ImageIO
CVE-ID: CVE-2009-2188
Available for: Windows XP and Vista
Impact: Viewing a maliciously crafted image may lead to an unexpected application termination or arbitrary code execution
Description: A buffer overflow exists in the handling of EXIF metadata. Viewing a maliciously crafted image may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue through improved bounds checking.

-Safari
CVE-ID: CVE-2009-2196
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.7, Mac OS X Server v10.5.7, Mac OS X v10.5.8, Mac OS X Server v10.5.8, Windows XP and Vista
Impact: A maliciously crafted website may be promoted into Safari's Top Sites view
Description: Safari 4 introduced the Top Sites feature to provide an at-a-glance view of a user's favorite websites. It is possible for a malicious website to promote arbitrary sites into the Top Sites view through automated actions. This could be used to facilitate a phishing attack. This issue is addressed by preventing automated website visits from affecting the Top Sites list. Only websites that the user visits manually can be included in the Top Sites list. As a note, Safari enables fraudulent site detection by default. Since the introduction of the Top Sites feature, fraudulent sites are not displayed in the Top Sites view. Credit to Inferno of SecureThoughts.com for reporting this issue.

-WebKit
CVE-ID: CVE-2009-2195
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.7, Mac OS X Server v10.5.7, Mac OS X v10.5.8, Mac OS X Server v10.5.8, Windows XP and Vista
Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution
Description: A buffer overflow exists in WebKit's parsing of floating point numbers. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue through improved bounds checking. Credit: Apple.

-WebKit
CVE-ID: CVE-2009-2200
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.7, Mac OS X Server v10.5.7, Mac OS X v10.5.8, Mac OS X Server v10.5.8, Windows XP and Vista
Impact: Visiting a maliciously crafted website and clicking "Go" when viewing a malicious plug-in dialog may lead to the disclosure of sensitive information
Description: WebKit allows the pluginspage attribute of the 'embed' element to reference file URLs. Clicking "Go" in the dialog that appears when an unknown plug-in type is referenced will redirect to the URL listed in the pluginspage attribute. This may allow a remote attacker to launch file URLs in Safari, and lead to the disclosure of sensitive information. This update addresses the issue by restricting the pluginspage URL scheme to http or https. Credit to Alexios Fakos of n.runs AG for reporting this issue.

-WebKit
CVE-ID: CVE-2009-2199
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.7, Mac OS X Server v10.5.7, Mac OS X v10.5.8, Mac OS X Server v10.5.8, Windows XP and Vista
Impact: Look-alike characters in a URL could be used to masquerade a website
Description: The International Domain Name (IDN) support and Unicode fonts embedded in Safari could be used to create a URL which contains look-alike characters. These could be used in a malicious website to direct the user to a spoofed site that visually appears to be a legitimate domain. This update addresses the issue by supplementing WebKit's list of known look-alike characters. Look-alike characters are rendered in Punycode in the address bar. Credit to Chris Weber of Casaba Security, LLC for reporting this issue.



Windows version users can get the latest version from Apple Downloads.

Thursday, July 9, 2009

Version 4.0.2 For Safari Available

Apple has released version 4.0.2 of its Safari web browser. New version fixes two vulnerabilities:
* WebKit

CVE-ID: CVE-2009-1724

Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.7, Mac OS X Server v10.5.7, Windows XP or Vista

Impact: Visiting a maliciously crafted website may lead to a cross-site scripting attack

Description: An issue in WebKit's handling of the parent and top objects may result in a cross-site scripting attack when visiting a maliciously crafted website. This update addresses the issue through improved handling of parent and top objects.

* WebKit

CVE-ID: CVE-2009-1725

Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.7, Mac OS X Server v10.5.7, Windows XP or Vista

Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution

Description: A memory corruption issue exists in WebKit's handling of numeric character references. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue through improved handling of numeric character references. Credit to Chris Evans for reporting this issue.


Windows version users can get the latest version from Apple Downloads.

Wednesday, June 10, 2009

Updated Version Of Apple Safari Available

Apple has released an updated version of Apple Safari web browser that fixes multiple vulnerabilities. Part of those allow an attacker to run arbitrary code in target system.

Affected are: Apple Safari for Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.7, Mac OS X Server v10.5.7, Windows XP or Vista versions prior 4.0.

Users of affected version should update by getting updated version here.

More information can be read from the correspondent support documentary.

Saturday, February 14, 2009

Safari 3.2.2 For Windows Released

Apple has released version 3.2.2 of its Safari browser for Windows.

New version fixes input validation issues in Safari’s handling of feed: URLs that could allow execution of arbitrary JavaScript in the local security zone.

More information on the fix here.

New version of Safari can be downloaded here.

Friday, November 14, 2008

Version 3.2 of Safari Web Browser Fixes Several Vulnerabilities

Apple has fixed totally 11 vulnerabilities in its Safari web browser. All vulnerabilities are related to Safari for Windows. Four of the vulnerabilities affect also Safari for Mac OS X (CVE-2008-3644, CVE-2008-2303, CVE-2008-2317 and CVE-2008-4216).

Apple updates contain fixes to the 3rd party libraries (zlib, libxslt, libTIFF and ImageIO). Among those patched are also CoreGraphics, WebCore and WebKit. Several of these patched vulnerabilities can be exploited by luring user to specially crafted website.

Vulnerable are following Safari versions:
- Safari for Mac OS X v10.4.11 prior version 3.2
- Safari for Mac OS X v10.5.5 prior version 3.2
- Safari for Windows XP prior version 3.2
- Safari for Windows Vista prior version 3.2

Users with vulnerable Safari can obtain version 3.2 either through Apple Software Update application or at http://www.apple.com/safari/download

More information on the vulnerabilities:

Security content of Safari 3.2
CVE-2005-2096
CVE-2008-1767
CVE-2008-2303
CVE-2008-2317
CVE-2008-2327
CVE-2008-2332
CVE-2008-3608
CVE-2008-3623
CVE-2008-3642
CVE-2008-3644
CVE-2008-4216

Saturday, June 21, 2008

Update For Safari For Windows Web Browser Released

There's been released an update for Windows version of Safari web browser. This update fixes four vulnerabilities.

  • Viewing a maliciously crafted BMP or GIF image may lead to information disclosure

  • Saving untrusted files to the Windows desktop may lead to the execution of arbitrary code

  • Visiting a malicious website which is in a trusted Internet Explorer zone may lead to the automatic execution of arbitrary code

  • A memory corruption issue exists in WebKit's handling of JavaScript arrays. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.


Safari users are instructed to update their versions to 3.1.2 version.

More information about update can be read on Apple's site.

Source