|
|||||||
| Register | Members List | New Posts | Mark Forums Read |
![]() |
|
|
Thread Tools | Display Modes |
|
|
#1 |
|
Kasper's Automated Slave
Join Date: Nov 1997
Posts: 6,148
|
Apple releases Safari 3.1.1 to address four security issues
Apple on Wednesday afternoon released version 3.1.1 of its Safari web browser to address a handful of security issues, including one widely publicized vulnerability that allowed a MacBook Air to be compromised during a recent security conference.
The 39MB release, available for both Macs and Windows PCs, is recommended for all Safari users and includes improvements to stability, compatibility and security. Specifically, Apple said the update patches four security issues, including a heap buffer overflow that existed within the browser's WebKit framework for handling JavaScript regular expressions. The issue was reported by Charlie Miller, who discovered and exploited the vulnerability on a MacBook Air to win a $10,000 prize at last month's CanSecWest security conference. The Safari 3.1.1 update also addressed a second issue within WebKit's handling of URLs containing a colon character in the host name. By exploiting that vulnerability, a hacker could use a maliciously crafted URL to lead a cross-site scripting attack, Apple said. Two other issues with the Safari application itself were also addressed, though they concerned only the PC version of the browser. One of those issues made it possible for a maliciously crafted website to control the contents of a user's address bar, while the other made it possible for maliciously crafted website to cause arbitrary code execution or the Safari application to unexpectedly quit. |
|
|
|
|
|
#2 |
|
Registered User
Join Date: Jan 2006
Posts: 502
|
Do they patch this kind of stuff in webkit in parallel?
File Encryption Tools Built Into Your Mac
|
|
|
|
|
|
#3 |
|
Registered User
Join Date: Nov 2001
Location: Southern CA
Posts: 1,265
|
I'm not liking this new safari 3.1.1. It's been doing weird things and it seems to hang.
|
|
|
|
|
|
#4 |
|
Registered User
Join Date: May 2006
Posts: 109
|
I noticed that too until I reset Safari. Now much better.
Switching From Windows on Nov. 30th 2007
|
|
|
|
|
|
#5 |
|
Global Moderator
Join Date: Jun 2004
Location: .US
Posts: 9,127
|
What's going on in Safari that requires a reboot to update? If it's that tightly integrated with the core of the OS, didn't that contribute to the security liability that took down the Air in that contest?
|
|
|
|
|
|
#6 |
|
Registered User
Join Date: Apr 2006
Location: The Ansible
Posts: 11,738
|
|
|
|
|
|
|
#7 | |
|
Registered User
Join Date: Mar 2006
Posts: 634
|
Quote:
I wasn't a fan of the firmware update a week or so ago. It was simple enough to do, but why did the user have to be involved. Firmware updates should be a little more automatic than having to depress a power button till a system beep goes off. Fun stuff!
Tory Hagen
Break the Wedge! |
|
|
|
|
|
|
#8 |
|
Global Moderator
Join Date: Jun 2004
Location: .US
Posts: 9,127
|
The first Mac Pro update required the user to hold the power button, but the second didn't.
Last edited by JeffDM; 04-16-2008 at 10:06 PM.. |
|
|
|
|
|
#9 | |
|
Registered User
Join Date: Nov 2004
Location: Northwest
Posts: 2,695
|
Quote:
WebKit is system-wide with the HTML Help system. |
|
|
|
|
|
|
#10 | |
|
Registered User
Join Date: Jul 2003
Posts: 2,478
|
Quote:
So far though it seems to work fine for me. |
|
|
|
|
|
|
#11 |
|
Registered User
Join Date: Jan 2008
Posts: 32
|
updated to 3.1.1 and no issues found
![]() |
|
|
|
|
|
#12 | |
|
Registered User
Join Date: Jun 2005
Posts: 85
|
Quote:
![]() Cheers Jan |
|
|
|
|
|
|
#13 |
|
Registered User
Join Date: May 2005
Location: Vancouver
Posts: 209
|
Youtube no longer works. Downloaded the newest flash player, and still doesn't work.
Great update ![]() |
|
|
|
|
|
#14 | |
|
Registered User
Join Date: Jun 2006
Location: South West Florida
Posts: 1,582
|
Quote:
Initially it seemed to have problems with any site I had been to recently but I only needed to clear cache to fix this, didn't need reset. Now all seems fine. |
|
|
|
|
|
|
#15 |
|
Registered User
Join Date: Mar 2008
Posts: 68
|
A lot of us still think that reseting Safari is the same option we had in previous versions.
Note that at this version and 3.1 too reseting Safari opens a window asking the user what to reset. So now reset is similar to Firefox's clear private data dialog box. I use it regularly to clean Safari. ![]() |
|
|
|
|
|
#16 |
|
Registered User
Join Date: Apr 2006
Location: The Ansible
Posts: 11,738
|
|
|
|
|
|
|
#17 |
|
Registered User
Join Date: Jan 2004
Location: Verde Amarela
Posts: 598
|
I like this new way. It seems like there will be fewer install problems because it's off a fresh boot, without any applications/processes running which may interfere with the update.
|
|
|
|
|
|
#18 |
|
Registered User
Join Date: Apr 2006
Location: The Ansible
Posts: 11,738
|
YOu're probably correct, but one thing I always touted OS X over Windows was taht simple updates didn't require restarts.
|
|
|
|
|
|
#19 |
|
Registered User
Join Date: Jun 2006
Location: Glasgow, Scotland
Posts: 4
|
I'm running safari 3.1.1 on a macbook running 10.4.11 - it's not a happy place.
I can;t get onto secure websites: firefox is fine with them but my banking, my email, university pages, my .Mac - which is being iffy today - are all being bounced in safari because it "couldn’t establish a secure connection to the server “www.amazon.co.uk”." - as an example. Any suggestions? |
|
|
|
|
|
#20 |
|
That's what she said!
Join Date: Apr 2005
Posts: 2,569
|
Updater gave me an error on my Mac Pro and now Safari won't work at all.
|
|
|
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
|
|