Apple updates Safari browser, busts 13 bugs
'Wow, Apple has to be careful,' researcher says
March 18, 2008 12:00 PM ETComputerworld - Apple Inc. today patched 13 vulnerabilities in Safari with an update that takes the browser to Version 3.1. (Read Computerworld's review of the new browser.)
The new Safari, which Apple proclaimed is "the world's fastest Web browser for Mac and Windows PCs," fixed 10 flaws afflicting both the Mac and Windows editions, and three that affect Safari for Windows XP and Windows Vista. The majority of the 13 vulnerabilities were cross-site scripting bugs.
"Wow, Apple has to be careful," said Andrew Storms, director of security operations at nCircle Network Security Inc. "Safari may not have any more bugs -- and fixes -- than IE and Firefox, but unleashing a giant package like this is going to create worry among users.
"When you release a dot-release version and its comes with a mother lode of vulnerabilities, that can bring down the favorable relationship that Apple has with its users," Storms said.
Only one of the patched bugs carried Apple's most dire warning -- that the flaw could result in "arbitrary code execution." Unlike competitors such as Microsoft Corp., Apple does not use a rating system to note the seriousness of individual vulnerabilities. Most vendors, however, rank flaws that let attackers execute malicious code as "high" or "extremely high."
Nine of the vulnerabilities -- eight on Mac OS X -- were classified by Apple as cross-site scripting flaws, which are often used by phishers and other identity thieves, but in some cases can be used to plant malware -- a Trojan horse, perhaps -- on a machine.
It's easy to dismiss cross-site scripting bugs, warned Storms, but doing so misses the big picture. "We've come to learn that cross-site scripting vulnerabilities are not the worst of the possible scenarios. But you have to understand where researchers are coming from. They're concentrating on cross-site scripting vulnerabilities, as well as other client-side [bugs]. It's all browsers these days."
Apple spelled out the details of the 13 bugs in a security advisory that accompanied the Safari 3.1 update.
The updated browser can be downloaded from Apple's Web site in versions for Mac OS X 10.4 (Tiger), Mac OS X 10.5 (Leopard), Windows XP and Windows Vista.
Apple
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
IDC White Paper: The Economic Impact of File Virtualization
Reduce costs and improve efficiency for file-based storage.
Aligning IT to Business: The Rising Importance of Application Delivery Networks
Application Delivery Networking (ADN) will play a vital role in helping enterprises incorporate strategic technologies to achieve business initiatives.
The 2009 Handbook of Application Delivery
Learn how to become better with application delivery.
Preparing Your Business Services for the Future
Would you trust your network monitoring tools enough to know when something is truly halting a business service?
Unified Application Delivery
By providing a unified Application Delivery Networking platform, F5 BIG-IP offers the ability for organizations to adopt a single platform for all its...
BMC Application Performance and Analytics: Predictive Intelligence in Action
See the highlights of BMC's Application Performance and Analytics today!
ROI of Application Delivery Controllers
How modern offload technologies in Application Delivery Controllers can drastically reduce expenses in traditional and virtualized architectures, with a fast ROI.
IPAM: Slashing Network Costs
Slashing Network Costs by Consolidating and Automating Core Network Services
Gartner: Magic Quadrant for Application Delivery Controllers, 2009
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing...
Key Strategies for Managing Data Growth
What are you storage challenges?
Computerworld Reports
Disaster Recovery & Cost Savings Zone
Thousands of customers world-wide have turned to virtualization solutions from Riverbed as a way to reduce costs.
