MAAS History
Archives
« Ransomeware, Scareware and Trojans are a Real Threat | Main | Office Update 2008 for Mac 12.2.4 Released »
Friday
Mar122010

APPLE-SA-2010-03-11-1 Safari 4.0.5

Apple has released a security update to Safari to 4.0.5 to address 10 issues including zero -days related to ColorSync, ImageIO and WebKit. Six additional issues affect the windows version of Safari. 

One issue is related to bypassing the blocking of cookies even if Safari is set to block them when using PubSub. PubSub is used for feed handling, cookies set by RSS and Atom feeds would be accepted even if Safari is set to block them. This implementation error has been corrected. Some of the vulnerabilities in WebKit center around the handling of CSS, HTML handling and XML documents resulting in memory corruption which can result in malicious code execution or application DOS.  One such vulnerability related to the handling of CSS format () arguments resulting in application DOS and malicious code execution is addressed with better memory tracking. Other issues include the handling of HTML element callback content, handling of right-to-left display text, use after free handling of incorrectly nested HTML tags and parsing of XML documents. Again, these WebKit issues are addressed by improving memory reference tracking. 

There are also a host of improvements in the handling of 3rd party plug-ins, stability improvements for Web sites that use forms, stability improvements in the handling of Scalable Vector Graphics and fixing an issue related to iWork.com users being unable to comment on documents. The installation does require a restart of the system and is critical, users should not surf the Web with Safari until this update is installed. 

PrintView Printer Friendly Version

EmailEmail Article to Friend

References (1)

References allow you to track sources for this article, as well as articles that were written in response to this article.

Reader Comments

There are no comments for this journal entry. To create a new comment, use the form below.
Member Account Required
You must have a member account on this website in order to post comments. Log in to your account to enable posting.