Vulnerabilities removed from Safari for Windows
Subscribe now and get the news that matters to your industry.
"Quotes and whitespace is now filtered on any requests to external URL protocol handler applications, but other characters are still being passed without filtering so I expect to find some variations pretty soon," Larholm wrote in his blog.
Apple officials noted that this flaw "does not pose a security issue on Mac OS X systems, but could lead to an unexpected termination of the Safari browser." The Safari 3 Public Beta for Mac has not been updated at this time.
The other two are an out-of-bounds memory read issue that may allow arbitrary code execution, and a cross-site scripting issue. Neither of these affect Mac OS X versions, according to the company.
This implies that the six vulnerabilities found by Errata Security's David Maynor remain unfixed, as he claimed they "work on the currently shipping Safari browser on OSX".
Maynor reportedly told Wired that he plans to hold onto an exploit he developed until he can buy an iPhone and break into it.
The Safari for Windows beta may be downloading from Apple's web site, or via the Apple Software Update application installed alongside QuickTime or iTunes for Windows.
Apple also announced that more than one million copies of Safari for Windows were downloaded in the 48 hours following its release.
PROTECT YOURSELF AGAINST BANDWIDTH BANDITS!Don't let traffic bottlenecks slow your network or business-critical apps to a grinding halt. With SolarWinds Bandwidth Analyzer Pack (BAP) you can gain unified network availability, performance, bandwidth, and traffic monitoring together in a single pane of glass.
With SolarWinds BAP, you'll be able to:
• Detect, diagnose, and resolve network performance issues
• Track response time, availability, and uptime of routers, switches, and other SNMP-enabled devices
• Monitor and analyze network bandwidth performance and traffic patterns.
• Identify bandwidth hogs and see which applications are using the most bandwidth
• Graphically display performance metrics in real time via dynamic interactive maps
Download FREE 30 Day Trial!
ITWIRE SERIES - IS YOUR BACKUP STRATEGY COSTING YOU CLIENTS?Where are your clients backing up to right now?
Is your DR strategy as advanced as the rest of your service portfolio?
What areas of your business could be improved if you outsourced your backups to a trusted source?
Read the industry whitepaper and discover where to turn to for managed backup
Stephen Withers is one of Australia¹s most experienced IT journalists, having begun his career in the days of 8-bit 'microcomputers'. He covers the gamut from gadgets to enterprise systems. In previous lives he has been an academic, a systems programmer, an IT support manager, and an online services manager. Stephen holds an honours degree in Management Sciences, a PhD in Industrial and Business Studies, and is a senior member of the Australian Computer Society.