Robert Vamosi | Nov 14, 2008

On Thursday, Apple released Safari 3.2. Although the update affects both Mac
and Windows users, many of the Mac updates were provided in
Apple's October update for Mac OS X
users. The update includes eight fixes specific to Safari and three specific to
Webkit.
Safari 3.2 is available via the Apple Software Update application, the
Apple Software Downloads
page, or
Apple's Safari download
site.
Safari-1This patch affects Safari users on Windows XP or Vista.
This update addresses multiple vulnerabilities in zlib 1.2.2 detailed within
CVE-2005-2096. Apple credits Robbie Joosten of bioinformatics@school, and David
Gunnells of the University of Alabama at Birmingham for reporting the
vulnerabilities.
Safari-2This patch affects users of Windows XP or Vista. This
update addresses the security issue in the libxslt library detailed within
CVE-2008-1767 in which processing an XML document may lead to an unexpected
application termination or arbitrary code execution. Apple credits Anthony de
Almeida Lopes of Outpost24 AB, and Chris Evans of the Google Security Team for
finding the vulnerability.
Safari-3This patch affects users of Windows XP or Vista. The
update addresses the heap buffer overflow issue that exists in the CoreGraphics'
handling of color spaces detailed within CVE-2008-3623 in which viewing a
maliciously crafted image may lead to an unexpected application termination or
arbitrary code execution. Apple credits itself for finding the vulnerability.
Safari-4This patch affects users of Windows XP or Vista. This
update addresses the security issue detailed within CVE-2008-2327 in which
viewing a maliciously crafted TIFF image may lead to an unexpected application
termination or arbitrary code execution. Apple credits itself for finding the
vulnerability.
Safari-5This patch affects users of Windows XP or Vista. The
update addresses the vulnerabilities detailed within CVE-2008-2332 in which
viewing a maliciously crafted TIFF image may lead to an unexpected application
termination or arbitrary code execution. Specifically, a memory corruption issue
exists in ImageIO's handling of embedded ICC profiles in JPEG images. Apple
credits Robert Swiecki of the Google Security Team for finding the
vulnerability.
Safari-6This patch affects users of Windows XP or Vista. This
update addresses the security issue detailed within CVE-2008-3608 in which
viewing a large maliciously crafted JPEG image may lead to an unexpected
application termination or arbitrary code execution. Apple credits itself for
finding the vulnerability.
Safari-7This patch affects users of Windows XP or Vista. This
update addresses the security issue detailed within CVE-2008-3642 in which
viewing a maliciously crafted image may lead to an unexpected application
termination or arbitrary code execution. Apple credits itself for finding the
vulnerability.
Safari-8This patch affects users of Mac OS X v10.4.11, Mac OS X
v10.5.5, or Windows XP or Vista. The update addresses the vulnerabilities
detailed within CVE-2008-3644 in which disabling autocomplete on a form field
may not prevent the data in the field from being stored in the browser page
cache. This may lead to the disclosure of sensitive information to a local user.
Apple credits an anonymous researcher for finding the vulnerability.
WebKit-1This patch affects users of Mac OS X v10.4.11, Mac OS X
v10.5.5, or Windows XP or Vista. This update addresses the security issue
detailed within CVE-2008-2303 in which visiting a maliciously crafted Web site
may lead to an unexpected application termination or arbitrary code execution.
Apple credits SkyLined of Google for finding the vulnerability.
WebKit-2This patch affects users of Mac OS X v10.4.11, Mac OS X
v10.5.5, and Windows XP or Vista. The update addresses the vulnerabilities
detailed within CVE-2008-2317 in which visiting a maliciously crafted Web site
may lead to an unexpected application termination or arbitrary code execution.
Specifically, a memory corruption issue exists in WebCore's handling of style
sheet elements. The issue has already been addressed in systems running Mac OS X
v10.5.5. Apple credits the TippingPoint Zero Day Initiative for finding the
vulnerability.
Webkit-3This patch affects users of Mac OS X v10.4.11, Mac OS X
v10.5.5, and Windows XP or Vista. This update addresses the security issue
detailed within CVE-2008-4216 in which visiting a maliciously crafted Web site
may lead to the disclosure of sensitive information. This update addresses the
issue by restricting the types of URLs that may be launched via the plug-in
interface. Apple credits Billy Rios of Microsoft, and Nitesh Dhanjani of Ernst
& Young for finding this vulnerability.
Via
CNET Blogs
To post comments, you need to become a member. It's FREE.