Stephen Withers
Friday, 14 November 2008 07:26
IT Industry -
Development
Page 2 of 2
Of the 11 security fixes, seven are Windows specific and the rest apply equally to Mac OS X 10.4, 10.5 and Windows.
The Windows update replaces an old version of zlib which contained multiple vulnerabilities (another example of Apple being slow to deliver the latest versions of open-source components).
It also corrects three cases of our old favourite, the buffer overflow. The specific bugs could be triggered by displaying a maliciously crafted web page containing XML or a maliciously crafted images.
Other Windows-specific vulnerabilities fixed in the new version meant maliciously crafted TIFF or JPEG images could cause the execution of arbitrary code. These problem had previously been fixed in Mac OS X 10.4.11 with Security Update 2008-006 and Mac OS X 10.5.5.
Three of the problems common to the Mac and Windows versions of Safari were located in WebKit, and involved JavaScript array handling, style sheets, and the ability to open local files via WebKit's plug-in interface.
The final fix in Safari 3.2 concerns the storage of form field data in the browser page cache, where it could be accessed by another local user.
Safari 3.2 is available via Software Update (Apple Software Update on Windows) or
Apple Downloads.
The updates vary in size from 19M for the Windows version to 39M for Leopard.