Got a tip for us? Share it...

Apple Releases Safari Beta 3.0.2, Security Update 2007-006

Apple has released an update to its Safari browser, Beta 3.0.2 for Mac and PC via its website and Software Update.

Changes in Safari 3.0.2 for Windows beta:
- Latest security updates
- Improved stability
- Fixes for text display, non-English systems, and start-up times

Changes in Safari 3.0.2 for Mac OS X beta:
-Latest security updates
-Improved stability
-Improved WebKit support for Mail, iChat and Dashboard


Also released today is Security Update 2007-006 for Mac OS 10.3.9 and Mac OS 10.4.9 and later. The update addresses two vulnerabilities in WebKit, one of which could lead to an unexpected application termination or arbitrary code execution. More information on the update can be found here.

Though still in beta, the initial release of Safari 3.0 had seen 8 vulnerabilities discovered within 24 hours of its release, some of which were cross-platform. Apple quickly released Safari 3.0.1 for Windows which addressed some of the Windows-specific vulnerabilities discovered.

Top Rated Comments

(View all)

61 months ago
The security update isn't showing up for me. :confused:
Rating: 0 Positives / 0 Negatives
61 months ago

The security update isn't showing up for me. :confused:


I haven't seen the security update in Software Update yet, but its on Apple's website.
Rating: 0 Positives / 0 Negatives
61 months ago
I think people with 10.4.10 don't need the security update.I tried to install it and it wouldn't let me.
Rating: 0 Positives / 0 Negatives
61 months ago
Me neither... I guess it needs some time, it always reaches some people first.
Rating: 0 Positives / 0 Negatives
61 months ago



Though still in beta, the initial release of Safari 3.0 had seen 8 vulnerabilities discovered within 24 hours of its release, some of which were cross-platform. Apple quickly released Safari 3.0.1 for Windows which addressed some of the Windows-specific vulnerabilities discovered.


So some of the Apple vulnerabilities haven't been fixed yet? I haven't downloaded Safari 3 myself (quite fond of Firefox) but I thought I'd check it out.
Rating: 0 Positives / 0 Negatives
61 months ago
I actually think that you won't get both updates if you are running the beta...since the security update patches WebKit, maybe it's part of the Safari beta update? And those not running the beta will get the security update?
Rating: 0 Positives / 0 Negatives
61 months ago
3.0.2 still didn't fix the fact that the white headlines within the red bar on the MR front page news items are wayyyy tooo booold. As is everything else. It is so thick and blurry. So much for text display fixes.
Rating: 0 Positives / 0 Negatives
61 months ago
WebCore

Visiting a malicious website may allow cross-site requestsAn HTTP injection issue exists in XMLHttpRequest when serializing headers into an HTTP request. By enticing a user to visit a maliciously crafted web page, an attacker could conduct cross-site scripting attacks. This update addresses the issue by performing additional validation of header parameters. Credit to Richard Moore of Westpoint Ltd. for reporting this issue.

WebKit

Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code executionAn invalid type conversion when rendering frame sets could lead to memory corruption. Visiting a maliciously crafted web page may lead to an unexpected application termination or arbitrary code execution. Credit to Rhys Kidd of Westnet for reporting this issue.
Rating: 0 Positives / 0 Negatives
61 months ago
Hmmm, looks like we will go to 3.0.97 rather fast.
Rating: 0 Positives / 0 Negatives
61 months ago

So some of the Apple vulnerabilities haven't been fixed yet? I haven't downloaded Safari 3 myself (quite fond of Firefox) but I thought I'd check it out.


yeah... 3.0.1 only addressed the Windows-specific vulnerabilities. Some folks took that to mean that the vulnerabilities that were found WERE only windows-specific, but that's not the case. Apple just took a little while to fix the rest of them. Even now, I'm not sure whether all of them have been patched, as a few more have been trickling out, although they haven't been as severe, hence why we haven't been covering them.
Rating: 0 Positives / 0 Negatives

[ Read All Comments ]