AppleInsider AppleInsider Forums


Go Back   AppleInsider > iPhone
Register Members List New Posts Mark Forums Read

Reply
 
Thread Tools Display Modes
Old 07-31-2007, 09:07 PM   #1
AppleInsider
Kasper's Automated Slave
 
Join Date: Nov 1997
Posts: 6,166
Apple's first iPhone software update addresses security, bugs

Apple on Tuesday evening addressed concerns about potentially dangerous security holes in the mobile version of its Safari web browser with the first ever software update to its new iPhone handset.

Targeting vulnerabilities that could be exploited through malicious websites, version 1.0.1 (build 1C25) of the handset's software updates Safari's JavaScript handling to prevent cross-site scripting and a buffer overflow in the Perl code library.

The latter scripting flaw was heavily publicized last week when consultants from Independent Security Evaluators used it to effectively hijack the phone's core functions.

Also addressed by software patch were three separate issues within the company's WebCore and WebKit platforms that form the backbone of Safari. Two of the fixes guard against false XML requests and frame rendering glitches that could be used to control the phone or crash the browser through memory errors.

Like recent iPod updates, the iPhone fix is downloadable solely through iTunes and can be installed the next time the phone is docked or detected by the jukebox software.

In a brief set of release notes, Apple said the iPhone software update also includes several "bug fixes." The company recommends that users install the patch "immediately."

AppleInsider is offline   Reply With Quote
Old 07-31-2007, 09:23 PM   #2
Rot'nApple
Registered User
 
Join Date: Feb 2007
Posts: 673
Quote:
Originally Posted by AppleInsider View Post
Apple has tackled concerns about potentially dangerous security holes in its mobile version of Safari with the first revision to the iPhone's code.

Tuesday marked the release of Apple's first ever fix for the iPhone since the product's June 29th release and mends vulnerabilities relating to visiting malicious websites.
First Post?! - Maybe...

Any word on whether this patch just deals with Safari? What about the little idiosyncrasies of the other apps on the phone and the wishlists that have been reported on or dreamed about. What is it's status, anyone?
Rot'nApple is offline   Reply With Quote
Old 07-31-2007, 09:23 PM   #3
mstone
Registered User
 
Join Date: Jan 2006
Location: SoCal
Posts: 942
Cool deal
mstone is offline   Reply With Quote
Old 07-31-2007, 09:59 PM   #4
donlphi
Registered User
 
Join Date: Jun 2006
Location: Seattle
Posts: 146
Goodbye ringtones

Anybody else have to restore their iPhone in order to install the update?

It killed my ringtones. As soon as it's done installing, I'll let you know if I can use Jailbreak again.


Last edited by donlphi; 07-31-2007 at 10:00 PM.. Reason: forgot to mention I used iFuntastic to edit my ringtone list
donlphi is offline   Reply With Quote
Old 07-31-2007, 10:06 PM   #5
ChristoRogers
Registered User
 
Join Date: Mar 2006
Location: Tokyo, Japan
Posts: 7
Quote:
Originally Posted by donlphi View Post
Anybody else have to restore their iPhone in order to install the update?

It killed my ringtones. As soon as it's done installing, I'll let you know if I can use Jailbreak again.
Yup. It gave me an error when trying to update normally when it was extracting or verifying, and now I'm restoring my iPhone as I type. It scared me at first because it was giving an unknown error when trying to restore, but it's working now...
ChristoRogers is offline   Reply With Quote
Old 07-31-2007, 10:58 PM   #6
sandau
Registered User
 
Join Date: Mar 2005
Posts: 1,010
flawless install.

and 1.0.1 1C25 is so much snappier than 1.0 (had to say it!!)

lol.

no new functionality but bug fixes are good before Aug 2!

I really hope a lot of cool stuff comes with Leopard for the Apple TV and iPhone.


:-D * * * * * * * * * * * * * * * *
sandau is offline   Reply With Quote
Old 07-31-2007, 11:01 PM   #7
desarc
Registered User
 
Join Date: Sep 2005
Posts: 244
hmmmm

iTunes will automatically check for an update again on 8/7/07.
isn't that the day that apple is supposed to announce iMacs? perhaps a bit more than iMacs?


--
16gb iPhone // 17" MBP core2duo, stock // 17" lampshade iMac G4 1Ghz
--
desarc is offline   Reply With Quote
Old 07-31-2007, 11:01 PM   #8
mrjoec123
Registered User
 
Join Date: Nov 2006
Posts: 222
Quote:
Originally Posted by ChristoRogers View Post
Yup. It gave me an error when trying to update normally when it was extracting or verifying, and now I'm restoring my iPhone as I type. It scared me at first because it was giving an unknown error when trying to restore, but it's working now...
I didn't need to restore, but I haven't used Jailbreak or any other hack.

So far so good. Safari seems to crash less often, but it's too early to be sure.
mrjoec123 is offline   Reply With Quote
Old 07-31-2007, 11:06 PM   #9
mrjoec123
Registered User
 
Join Date: Nov 2006
Posts: 222
Quote:
Originally Posted by desarc View Post
iTunes will automatically check for an update again on 8/7/07.
isn't that the day that apple is supposed to announce iMacs? perhaps a bit more than iMacs?
Aug 7 is a week from today. iTunes checks every week automatically. Don't read too much into it.

Apple itself was very clear that there will only be Mac-related announcements on the 7th.
mrjoec123 is offline   Reply With Quote
Old 07-31-2007, 11:35 PM   #10
Proximityeffect
Registered User
 
Join Date: Jul 2007
Posts: 47
Easy install here.
Proximityeffect is offline   Reply With Quote
Old 08-01-2007, 12:39 AM   #11
psychobass213
Registered User
 
Join Date: Jan 2003
Location: NJ
Posts: 41
So has anyone tried re-installing ringtones after updating their iPhones?
psychobass213 is offline   Reply With Quote
Old 08-01-2007, 12:45 AM   #12
Ireland
Registered User
 
Join Date: Feb 2006
Location: Ireland
Posts: 8,564
Quote:
Originally Posted by mrjoec123 View Post
Aug 7 is a week from today. iTunes checks every week automatically. Don't read too much into it.

Apple itself was very clear that there will only be Mac-related announcements on the 7th.
Yet I can guarantee the crowds will try to persuade them wrong.


Collecting my SSD iMac Fry-die. :D
Ireland is offline   Reply With Quote
Old 08-01-2007, 04:48 AM   #13
michaelb
Registered User
 
Join Date: Jan 2003
Posts: 223
Wink

Quote:
Originally Posted by mrjoec123 View Post
Apple itself was very clear that there will only be Mac-related announcements on the 7th.
I don't buy it. I think it was just a clever ruse to keep Wall Street from sending Apple stock over $300 and 270,000 hit man contracts issued on Steve when he announces:

"iPhone 2.0 - you've had the demo, now get the real thing. This one is 3G, has GPS functionality, Notes syncing, multiple email delete, and all those other bullet point wishlists that the suckers were waiting for with the 1.x update."

"One more thing... no AT&T."

Or of course it could be an iMac with a squished keyboard. Take your pick!
michaelb is offline   Reply With Quote
Old 08-01-2007, 04:55 AM   #14
Walter Slocombe
Registered User
 
Join Date: Apr 2007
Posts: 1,567
Quote:
Originally Posted by AppleInsider View Post
Targeting vulnerabilities that could be exploited through malicious websites, version 1.0.1 (build 1C25) of the handset's software updates Safari's JavaScript handling to prevent cross-site scripting and a buffer overflow in the Perl code library.
So am I right in thinking that in part Java is to blame? if so then Apple are right to leave it off the iPhone, it wouldnt be the first time Java has bit them.


I don't see how an anti M$ stance can be seen as a bad thing on an Apple forum I really can't!

nagromme - According to Amazon: "SpongBob Typing Tutor" is outselling Windows
Walter Slocombe is offline   Reply With Quote
Old 08-01-2007, 06:13 AM   #15
palegolas
Registered User
 
Join Date: May 2005
Posts: 383
How big is this update?
I'm just curious of generally how big a system update for (portable) OS X is.
palegolas is offline   Reply With Quote
Old 08-01-2007, 06:34 AM   #16
tsvisser
Registered User
 
Join Date: Jun 2006
Posts: 36
Quote:
Originally Posted by Walter Slocombe View Post
So am I right in thinking that in part Java is to blame? if so then Apple are right to leave it off the iPhone, it wouldnt be the first time Java has bit them.
in this case, no that is not correct. javascript is not related to java, despite the fact that both use "java" in the name. at least, they are not related technologies in that a platform that does not support java does not say anything about it supporting javascript. iPhone's Safari does in fact support javascript and the vulnerability had nothing to do with java or their decision to not include its support.
tsvisser is offline   Reply With Quote
Old 08-01-2007, 07:35 AM   #17
Bacillus
Registered User
 
Join Date: Oct 2006
Posts: 313
It does not fix the polka dots issue.


Report employers of illegal aliens at (866) DHS-2ICE
Bacillus is offline   Reply With Quote
Old 08-01-2007, 09:45 AM   #18
PBG4 Dude
Registered User
 
Join Date: Nov 2001
Location: CT
Posts: 1,538
Quote:
Originally Posted by Walter Slocombe View Post
So am I right in thinking that in part Java is to blame? if so then Apple are right to leave it off the iPhone, it wouldnt be the first time Java has bit them.
Javascript != Java

Very important to know, and javascript is available on the iPhone or else "Web 2.0" wouldn't work on it.


20" iMac G5 now with 2GB RAM. :-)

Check out my OS X music program!
PBG4 Dude is offline   Reply With Quote
Old 08-01-2007, 10:14 AM   #19
physguy
Registered User
 
Join Date: May 2002
Posts: 834
I've found only one specific bug that was fixed. Previously the iPhone would not remember by VPN password, now it does. If you don't enter a password it still only gives the numbers keypad to enter the password when you start VPN so that wasn't fixed. Also, the Stopwatch/Lap bug was not fixed.
physguy is offline   Reply With Quote
Old 08-01-2007, 10:23 AM   #20
Bacillus
Registered User
 
Join Date: Oct 2006
Posts: 313
Quote:
Originally Posted by psychobass213 View Post
So has anyone tried re-installing ringtones after updating their iPhones?
Yes - I used iFuntastic 2.1.0, and it worked.


Report employers of illegal aliens at (866) DHS-2ICE
Bacillus is offline   Reply With Quote
Old 08-01-2007, 11:57 AM   #21
violo25
Registered User
 
Join Date: Aug 2007
Posts: 16
Really quick install, about 5 minutes.
It is curious, that updating has not been published on site of Apple and is accessible only through a player iTunes. Thus installation process is shown on computer display, instead of on the display of iPhone itself.


iPhone Mania Has You...

PROBABLY BIGGEST APPLE IPHONE COMMUNITY
violo25 is offline   Reply With Quote
Old 08-01-2007, 12:33 PM   #22
bitWrangler
Registered User
 
Join Date: Jul 2007
Posts: 12
No problems here with the update. It did seem to "pause" for a while in the middle (the progress bar did not advance in iTunes or the iPhone, but that only lasted for a couple of minutes. I am happy to get the update as I've had Safari crap out on me multiple times and yesterday the phone freaked out (the home screen refreshed continuously about once every second).
bitWrangler is offline   Reply With Quote
Old 08-01-2007, 02:23 PM   #23
filburt
Registered User
 
Join Date: Jul 2004
Location: Bay Area, CA
Posts: 286
Quote:
Originally Posted by sandau View Post
flawless install.

and 1.0.1 1C25 is so much snappier than 1.0 (had to say it!!)
In all seriousness, many are reporting the same thing but I think it's the requisite reboot that explains snappier performance.
filburt is offline   Reply With Quote
Old 08-01-2007, 03:38 PM   #24
physguy
Registered User
 
Join Date: May 2002
Posts: 834
Quote:
Originally Posted by filburt View Post
In all seriousness, many are reporting the same thing but I think it's the requisite reboot that explains snappier performance.
Not in my case as I have rebooted several times, on general principle, during the 4 weeks I've had the phone. It is currently 'snappier' than at any time before the update. For example playing the 'Bejewled' game (which is local javascript once loaded) is visibly faster in updating the screen after a move.


Last edited by physguy; 08-01-2007 at 10:23 PM.. Reason: various typos
physguy is offline   Reply With Quote
Old 08-01-2007, 07:54 PM   #25
Mojo
Registered User
 
Join Date: Aug 2007
Posts: 1
Happy iphone

after running the update today, my exchange account is working perfectly with all the various subfolders showing up and syncing with iphoto finally works correctly for me. Before the update, I had problems with photos not deleting from the iphone after being imported to iphoto and thats been resolved as well
Mojo is offline   Reply With Quote
Old 08-02-2007, 09:11 PM   #26
cyko95
Registered User
 
Join Date: May 2002
Location: St. Louis Area
Posts: 376
This may be simply my mail server's problem, but has anyone else noticed emails taking a LOT longer to send out than before the update? No matter if i'm on wifi or edge it takes at least a couple minutes or so now. Before it was like 15 - 20 seconds.


Don't click here, addictions may follow!

2ghz Intel Macbook
1.6Ghz Intel Mini
4GB iPhone
cyko95 is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 11:35 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.