No. 1 Story

Technology reinforces generation gap

If you believe that technology could be bridging the generation gap, think again. According to Deloitte’s first State of the Media report it’s as stark as ever.

read more

Related Articles

Safari, includes, security, fixes
While most users will regard security as the most pressing reason to install Microsoft's...
Microsoft has targeted business customers with a new range of integrated security and management...
Apple has re-released Security Update 2007-004 to correct a pair of problems affecting certain...
The MoAB Fixes team has updated its run-time patching software to take account of...
Apple's latest QuickTime software patches a slew of security vulnerabilities in the Mac OS...

Safari 3.1 includes security fixes

Business IT - Technology

Even if you're not moved by Apple's claims about Safari 3.1's speed, there are other good reasons to install the new version.

Most of the security fixes in Safari proper are specific to the Windows version as those issues have already been solved (or never existed in) Mac OS X.

These relate to SSL certificate validation (fixed by Security Update 2007-008, Mac OS X 10.4.11 and 10.5 or later), proxy servers that deliver fake copies of secure pages (fixed in Mac OS X 10.5.2 or Security Update 2008-002 for Mac OS X 10.4.11) or a certain cross-site scripting attack that does not affect Mac OS X.

Another cross-site scripting attack - one that uses exploits a flaw in the handling of javascript: URLs - is addressed on both platforms. Safari 3.1 carries out additional validation to prevent malicious sites from causing the execution of JavaScript in another site's context.

Another nine fixes have been applied to the WebCore and WebKit frameworks used by Safari and other applications, and these affect Mac OS X and Windows.

Seven of them relate to cross-site scripting vulnerabilities, another is an 'over the shoulder' vulnerability (it seems the Kotoeri input method sometimes failed to display the contents of password input fields as bullets)  and the ninth is another example of our old favourite, the buffer overflow issue with the possibility of executing arbitrary code.

Apple also claims Safari 3.1 is the first browser to support the new video and audio tags in HTML 5 and the first to support CSS Animations.

CONTINUED