Apple Patches Safari Vulnerabilities - InformationWeek

InformationWeek is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Infrastructure // PC & Servers
01:57 PM
Connect Directly

Apple Patches Safari Vulnerabilities

The fixes include patching a zero-day vulnerability in Apple's Web browser that allowed researchers to compromise a MacBook Air.

Apple on Wednesday issued a security patch for its Safari Web browser that fixes a widely reported vulnerability and three other holes, two of which affect only Windows versions.

At the CanSecWest security conference last month, security researchers Charlie Miller, Jake Honoroff, and Mark Daniel, from Independent Security Evaluators, managed to compromise a MacBook Air using a zero-day vulnerability in Safari.

Tipping Point, the sponsor of the contest, said the vulnerability would not be disclosed until Apple issued a patch.

Among the four vulnerabilities fixed in Wednesday's Safari patch is CVE-2008-1026, which Apple thanked Miller for reporting.

Apple describes the flaw thus: "A heap buffer overflow exists in WebKit's handling of JavaScript regular expressions. The issue may be triggered via JavaScript when processing regular expressions with large, nested repetition counts. This may lead to an unexpected application termination or arbitrary code execution."

To fix the problem, Apple said it added validation to JavaScript regular expressions.

A second WebKit vulnerability was also addressed. WebKit is an open source engine used by Apple's Safari, Mail, and other applications. Both WebKit issues affect Mac and Windows users of Safari.

The other two vulnerabilities affect only Safari for Windows XP or Vista. One is a timing flaw that could allow a maliciously crafted Web page to spoof a legitimate site by changing the contents of Safari's address bar without loading the associated page. The other is a memory corruption issue that could allow for the remote execution of malware following an attempt to download a maliciously crafted file.

The Safari patch can be downloaded through the Mac OS X Software Update control panel, or from Apple's Web site.

Safari's share of the browser market remained relatively flat throughout 2007, at about 1.7%, according to W3Schools. It has become more popular, however, in 2008. In March, Safari had a 2.1% market share. Microsoft's various versions of Internet Explorer accounted for 53.1% of the visitors to the W3Schools site in March, while Firefox accounted for 37%.

We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.
Comment  | 
Print  | 
More Insights
2021 Outlook: Tackling Cloud Transformation Choices
Joao-Pierre S. Ruth, Senior Writer,  1/4/2021
Enterprise IT Leaders Face Two Paths to AI
Jessica Davis, Senior Editor, Enterprise Apps,  12/23/2020
10 IT Trends to Watch for in 2021
Cynthia Harvey, Freelance Journalist, InformationWeek,  12/22/2020
White Papers
Register for InformationWeek Newsletters
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you.
Flash Poll