Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Apple

June 9th, 2010, 13:19 GMT · By

Apple Plugs 48 Security Holes in Safari 5, Safari 4.1

SHARE:

Adjust text size:


Safari application icon
Enlarge picture
While Safari 5 (for Leopard, Snow Leopard and Windows) and Safari 4.1 (for Tiger) address the same set of security issues, the majority of the vulnerabilities documented by Apple affect WebKit, the open-source engine powering the browser. A total of 48 security holes have been plugged by the Mac maker, according to a knowledge base article posted on the Support section of Apple’s website.

Over at Apple’s Support area, tech note HT4196 delves deep into the security content of Safari 5.0 and Safari 4.1. Most of the addressed issues are pretty serious. Most of them were also found in WebKit, as noted above. A list of some of the most severe plugged holes can be found below, as described by Apple.

· ColorSync
CVE-2009-1726 —
A heap buffer overflow exists in the handling of images with an embedded ColorSync profile. Opening a maliciously crafted image with an embedded ColorSync profile may lead to an unexpected application termination or arbitrary code execution.
· Safari
CVE-2010-1384 —
Safari supports the inclusion of user information in URLs, which allows the URL to specify a username and password to authenticate the user to the named server. These URLs are often used to confuse users, which can potentially aid phishing attacks.

· Safari
CVE-2010-1385 —
A use after free issue exists in Safari’s handling of PDF files. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.
· Safari
CVE-2010-1750 —
A use after free issue exists in Safari’s management of windows. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.
· WebKit
CVE-2010-1392 —
A use after free issue exists in WebKit’s rendering of HTML buttons. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.
· WebKit
CVE-2010-1119 —
A use after free issue exists in WebKit’s handling of attribute manipulation. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.
· WebKit
CVE-2010-1422 —
An implementation issue exists in WebKit’s handling of keyboard focus. If the keyboard focus changes during the processing of key presses, WebKit may deliver an event to the newly-focused frame, instead of the frame that had focus when the key press occurred. A maliciously crafted website may be able to manipulate a user into taking an unexpected action, such as initiating a purchase.


Download Safari for Mac OS X (Free)

Download Safari for Windows (Free)

TELL US WHAT YOU THINK:

1,312 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Mac-Inspired Dating Site Goes Live - Cupidtino

Microsoft Updates Office for Mac, Plans to Take On Apple’s iLife

iOS 4 Jailbreak Achieved for iPhone 3G and iPhone 3GS - redsn0w, PwnageTool

Mac OS X 10.6.4 Not Out Just Yet - Build 10F566 Seeded to Devs

Download Google Chrome 5.0.375.70 Stable for Mac OS X

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM