Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Apple

May 13th, 2009, 08:03 GMT · By

Download New Safari 4 Beta / 3.2.3 for Mac and Windows

SHARE:

Adjust text size:


Safari icon
Enlarge picture
Alongside the release of Mac OS X 10.5.7, Apple has issued an update for Safari users. Bringing the version number to 3.2.3 on both Mac and Windows platforms, the company has addressed three critical security issues in the browser, detailing each and every one in two Support pieces on its website. Both the Safari 4 Public Beta and Safari 3.2.3 have received the fixes, while users are strongly encouraged to download and install the update.

According to Apple, Safari suffered from three major security issues reported by Billy Rios of Microsoft Vulnerability Research (MSVR), and Alfredo Melloni and Nils, working with TippingPoint's Zero Day Initiative.

The support documents containing details about the security content of Safari 3.2.3 and Safari 4 Public Beta reveal that a heap buffer overflow exists in libxml's handling of long entity names. According to Apple, visiting a maliciously crafted website may lead to an unexpected application termination or to arbitrary code execution. The company proceeded to include a patch for this issue, addressing it through improved bounds checking in both versions of Safari (3.2.3 and 4 Beta), as well as on the Windows side. Tiger users are also affected by the problem, so updating is necessary.

Available only for Mac OS X v10.5.7, Mac OS X Server v10.5.7, Windows XP or Vista, multiple input validation issues exist in Safari's handling of "feed:" URLs, Apple has learned thanks to the research done by Billy Rios of Microsoft Vulnerability Research (MSVR), and Alfredo Melloni. Accessing a maliciously crafted "feed:" URL may lead to the execution of arbitrary JavaScript, the duo have found. The update available for Safari users today contains a patch for this issue as well. The fix was possible by performing additional validation of "feed:" URLs. Systems running Mac OS X versions lower than 10.5 are not affected, while the patch has already been included in Mac OS X 10.5.7, as well as in Security Update 2009-002.

Lastly, Apple reports a WebKit problem available for Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.7, Mac OS X Server v10.5.7, and Windows XP or Vista. The Mac maker has learned that a memory corruption issue exists in WebKit's handling of SVGList objects, thanks to tests carried out by Nils working with TippingPoint's Zero Day Initiative.

"Visiting a maliciously crafted website may lead to arbitrary code execution," the support document reads. "This update addresses the issue through improved bounds checking. This issue is addressed in Safari 3.2.3," the description ends.

As noted above, Safari 3.2.3 is included in the Mac OS X v10.5.7 Update. The latest version of Leopard is actually required so that Safari 3.2.3 can work on Mac OS X, as is Mac OS X v10.4.11 (on Tiger-running machines) with Security Update 2009-002 installed.

Download Safari 3.2.3 for Mac

Download Safari 3.2.3 for Windows

Download Safari 4 Public Beta

TELL US WHAT YOU THINK:

7,419 hits · 2 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Mac OS X 10.5.7 Available – Download Here

BitTorrent iPhone App Rejected Over Copyright Claims

McAfee Security for Mac 1.0 Beta 1 – Free Download

Apple Puts the Lock on Snow Leopard APIs – Developer Notes

iPhone OS 3.0 Boasts Magnetometer / Digital Compass Support (Rumor)

READER COMMENTS:


Comment #1 by: Tom Gabriel on 18 May 2009, 17:51 UTC reply to this comment

I used Software Updater to install Safari 3.2.3 update for OS X 10.4.11, which ran very well, fast and stable, for about five minutes. Then it began freezing loading pages, even ones it had visited previously in the same session. Has anyone else had this experience?


Comment #2 by: Chaupa on 25 Jan 2012, 09:28 UTC reply to this comment

Isn't there any safari 4 beta for windows?

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM