AppleInsider AppleInsider Forums


Go Back   AppleInsider > Applications
Register Members List New Posts Mark Forums Read

Reply
 
Thread Tools Display Modes
Old 04-16-2008, 05:58 PM   #1
AppleInsider
Kasper's Automated Slave
 
Join Date: Nov 1997
Posts: 6,148
Apple releases Safari 3.1.1 to address four security issues

Apple on Wednesday afternoon released version 3.1.1 of its Safari web browser to address a handful of security issues, including one widely publicized vulnerability that allowed a MacBook Air to be compromised during a recent security conference.

The 39MB release, available for both Macs and Windows PCs, is recommended for all Safari users and includes improvements to stability, compatibility and security.

Specifically, Apple said the update patches four security issues, including a heap buffer overflow that existed within the browser's WebKit framework for handling JavaScript regular expressions.

The issue was reported by Charlie Miller, who discovered and exploited the vulnerability on a MacBook Air to win a $10,000 prize at last month's CanSecWest security conference.

The Safari 3.1.1 update also addressed a second issue within WebKit's handling of URLs containing a colon character in the host name. By exploiting that vulnerability, a hacker could use a maliciously crafted URL to lead a cross-site scripting attack, Apple said.

Two other issues with the Safari application itself were also addressed, though they concerned only the PC version of the browser. One of those issues made it possible for a maliciously crafted website to control the contents of a user's address bar, while the other made it possible for maliciously crafted website to cause arbitrary code execution or the Safari application to unexpectedly quit. 

AppleInsider is offline   Reply With Quote
Old 04-16-2008, 06:49 PM   #2
walshbj
Registered User
 
Join Date: Jan 2006
Posts: 502
Do they patch this kind of stuff in webkit in parallel?


File Encryption Tools Built Into Your Mac
walshbj is offline   Reply With Quote
Old 04-16-2008, 07:35 PM   #3
sc_markt
Registered User
 
Join Date: Nov 2001
Location: Southern CA
Posts: 1,265
Quote:
Originally Posted by walshbj View Post
Do they patch this kind of stuff in webkit in parallel?
I'm not liking this new safari 3.1.1. It's been doing weird things and it seems to hang.


sc_markt is offline   Reply With Quote
Old 04-16-2008, 07:42 PM   #4
internetworld7
Registered User
 
Join Date: May 2006
Posts: 109
Quote:
Originally Posted by sc_markt View Post
I'm not liking this new safari 3.1.1. It's been doing weird things and it seems to hang.
I noticed that too until I reset Safari. Now much better.


Switching From Windows on Nov. 30th 2007
internetworld7 is offline   Reply With Quote
Old 04-16-2008, 07:47 PM   #5
JeffDM
Global Moderator
 
Join Date: Jun 2004
Location: .US
Posts: 9,127
What's going on in Safari that requires a reboot to update? If it's that tightly integrated with the core of the OS, didn't that contribute to the security liability that took down the Air in that contest?
JeffDM is offline   Reply With Quote
Old 04-16-2008, 08:00 PM   #6
solipsism
Registered User
 
Join Date: Apr 2006
Location: The Ansible
Posts: 11,738
Quote:
Originally Posted by JeffDM View Post
What's going on in Safari that requires a reboot to update?
My concerns as well. I'm not a fan of teh way Leopard goes into another mode to install system updates, requires more reboots for regular apps and that the updates seem overly large in size.
solipsism is online now   Reply With Quote
Old 04-16-2008, 09:43 PM   #7
MacTel
Registered User
 
Join Date: Mar 2006
Posts: 634
Quote:
Originally Posted by solipsism View Post
My concerns as well. I'm not a fan of teh way Leopard goes into another mode to install system updates, requires more reboots for regular apps and that the updates seem overly large in size.
Typically, if they are updating shared libraries that other apps using then they require a reboot.

I wasn't a fan of the firmware update a week or so ago. It was simple enough to do, but why did the user have to be involved. Firmware updates should be a little more automatic than having to depress a power button till a system beep goes off. Fun stuff!


Tory Hagen
Break the Wedge!
MacTel is offline   Reply With Quote
Old 04-16-2008, 09:52 PM   #8
JeffDM
Global Moderator
 
Join Date: Jun 2004
Location: .US
Posts: 9,127
Quote:
Originally Posted by MacTel View Post
I wasn't a fan of the firmware update a week or so ago. It was simple enough to do, but why did the user have to be involved. Firmware updates should be a little more automatic than having to depress a power button till a system beep goes off. Fun stuff!
The first Mac Pro update required the user to hold the power button, but the second didn't.


Last edited by JeffDM; 04-16-2008 at 10:06 PM..
JeffDM is offline   Reply With Quote
Old 04-16-2008, 10:54 PM   #9
mdriftmeyer
Registered User
 
Join Date: Nov 2004
Location: Northwest
Posts: 2,695
Quote:
Originally Posted by JeffDM View Post
What's going on in Safari that requires a reboot to update? If it's that tightly integrated with the core of the OS, didn't that contribute to the security liability that took down the Air in that contest?
WebKit and other System Frameworks are getting updated, new linking and more.

WebKit is system-wide with the HTML Help system.
mdriftmeyer is offline   Reply With Quote
Old 04-17-2008, 05:08 AM   #10
wizard69
Registered User
 
Join Date: Jul 2003
Posts: 2,478
Quote:
Originally Posted by sc_markt View Post
I'm not liking this new safari 3.1.1. It's been doing weird things and it seems to hang.
I'm not sure which web site you are having issues with but I did notice my Yahoo Mail account having problems that started just before the Safari update. So in that case at least it is not an update issue.

So far though it seems to work fine for me.
wizard69 is offline   Reply With Quote
Old 04-17-2008, 06:43 AM   #11
.mac
Registered User
 
Join Date: Jan 2008
Posts: 32
updated to 3.1.1 and no issues found
.mac is offline   Reply With Quote
Old 04-17-2008, 06:53 AM   #12
irchs
Registered User
 
Join Date: Jun 2005
Posts: 85
Quote:
Originally Posted by internetworld7 View Post
I noticed that too until I reset Safari. Now much better.
I noticed it also, a reset seems to fix it

Cheers

Jan


Jan

http://theFruitSoup.com - http://ColinClose.com/ - Download some free music I am involved in!
irchs is offline   Reply With Quote
Old 04-17-2008, 07:17 AM   #13
rain
Registered User
 
Join Date: May 2005
Location: Vancouver
Posts: 209
Youtube no longer works. Downloaded the newest flash player, and still doesn't work.
Great update
rain is offline   Reply With Quote
Old 04-17-2008, 11:33 AM   #14
digitalclips
Registered User
 
Join Date: Jun 2006
Location: South West Florida
Posts: 1,582
Quote:
Originally Posted by rain View Post
Youtube no longer works. Downloaded the newest flash player, and still doesn't work.
Great update
YouTube works fine for me.

Initially it seemed to have problems with any site I had been to recently but I only needed to clear cache to fix this, didn't need reset. Now all seems fine.
digitalclips is offline   Reply With Quote
Old 04-18-2008, 02:37 AM   #15
Nano_tube
Registered User
 
Join Date: Mar 2008
Posts: 68
A lot of us still think that reseting Safari is the same option we had in previous versions.
Note that at this version and 3.1 too reseting Safari opens a window asking the user what to reset.
So now reset is similar to Firefox's clear private data dialog box.

I use it regularly to clean Safari.

Nano_tube is offline   Reply With Quote
Old 04-18-2008, 10:41 AM   #16
solipsism
Registered User
 
Join Date: Apr 2006
Location: The Ansible
Posts: 11,738
Quote:
Originally Posted by Nano_tube View Post
Note that at this version and 3.1 too reseting Safari opens a window asking the user what to reset.
So now reset is similar to Firefox's clear private data dialog box.
I did not know this. Thanks.
solipsism is online now   Reply With Quote
Old 04-18-2008, 10:54 AM   #17
k squared
Registered User
 
Join Date: Jan 2004
Location: Verde Amarela
Posts: 598
Quote:
Originally Posted by solipsism View Post
My concerns as well. I'm not a fan of teh way Leopard goes into another mode to install system updates, requires more reboots for regular apps and that the updates seem overly large in size.
I like this new way. It seems like there will be fewer install problems because it's off a fresh boot, without any applications/processes running which may interfere with the update.
k squared is offline   Reply With Quote
Old 04-18-2008, 10:59 AM   #18
solipsism
Registered User
 
Join Date: Apr 2006
Location: The Ansible
Posts: 11,738
Quote:
Originally Posted by k squared View Post
I like this new way. It seems like there will be fewer install problems because it's off a fresh boot, without any applications/processes running which may interfere with the update.
YOu're probably correct, but one thing I always touted OS X over Windows was taht simple updates didn't require restarts.
solipsism is online now   Reply With Quote
Old 04-18-2008, 03:14 PM   #19
ensee
Registered User
 
Join Date: Jun 2006
Location: Glasgow, Scotland
Posts: 4
I'm running safari 3.1.1 on a macbook running 10.4.11 - it's not a happy place.

I can;t get onto secure websites: firefox is fine with them but my banking, my email, university pages, my .Mac - which is being iffy today - are all being bounced in safari because it "couldn’t establish a secure connection to the server “www.amazon.co.uk”." - as an example.

Any suggestions?
ensee is offline   Reply With Quote
Old 04-19-2008, 04:33 PM   #20
icfireball
That's what she said!
 
Join Date: Apr 2005
Posts: 2,569
Updater gave me an error on my Mac Pro and now Safari won't work at all.
icfireball is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 05:17 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.