Apple bugs
Apple has issued a second security update for its Windows Safari browser

Four more fixes for Windows Safari

Security updates pile up for Apple browser

Written by Shaun Nichols in California

Apple has issued a second security update for the Windows Safari browser less than two weeks after its launch.  

The four security fixes are part of a larger Safari 3.0.2 beta release for Mac OS X and Windows. Both packs contain stability fixes in addition to the security update.

Only one of the four vulnerabilities for the Windows version could allow for remote code execution. The flaw lies in the WebKit component used by Safari.

This could be exploited by an attacker to launch an exploit by directing the user to a specially crafted webpage. This page could cause an application crash and give the attacker the ability to install malware on the victim's computer.

Two of the vulnerabilities could leave users open to cross-site scripting attacks, while the remaining flaw gave attackers the ability to spoof legitimate websites.

One vulnerability allows attackers to conduct cross-site scripting attacks by using specially-crafted JavaScript code to redirect the user, while another allows cross-site scripting via a malformed HTTP request coded into a web page.

The fourth vulnerability allows an attacker arbitrarily to edit the information that appears in the URL bar. An attacker could exploit the vulnerability to make a malicious site appear with the URL of a trusted one.

Mac users will see two security fixes in the Safari update. Both the WebKit and HTTP-injection vulnerabilities affect OS X as well as Windows.

The updates also contain stability fixes for 16 performance and stability bugs in Windows and nine in OS X.

Tags:

Further reading

Apple plugs three Windows Safari holes

Firm scrambles to fix flaws in newly launched Windows browser   More...

Apple celebrates 1m Windows Safari downloads

Windows users flock to Macware to kick its tyres   More...

Apple brings Safari to Windows

'The fastest browser on Windows,' Jobs claims   More...

Security flaw hits Safari on Windows

Researcher demolishes Apple's security claims   More...

Related articles

Apple patches critical Safari holes

Four flaws addressed in latest update   More...

Mega Apple patch fixes iPhone, Safari, OS X bugs

Update repairs 54 vulnerabilities   More...

Mozilla issues 'critical' Firefox fixes

Update addresses a number of security issues   More...

Apple issues major OS X security update

Safari also patched   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

16 May 2008

2.97 MBXP on OLPC, broken dreams and Yahoo fights back More...

15 May 2008

3.28 MBDark fibre, mobile TV and solar power More...

14 May 2008

2.66 MBOnline inequality, mobile thumbprints and corporate raids More...

Poll

HOME WORKING

HOME WORKING

Do you let any or all of your employees work from home?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

OLPC

OLPC to ship with Windows XP

Microsoft teams up with One Laptop per Child project   More...

The Sims

The Sims goes flat-pack with Ikea

Virtual world gets Swedish wood   More...

Advertisement

Microsoft-Yahoo

Yahoo board fights back at Icahn

Investor accused of 'significant misunderstanding' in Microsoft saga   More...

MySpace

Woman charged over MySpace suicide

Lori Drew indicted on federal charges   More...

Advertisement