Got a tip for us? Share it...

Apple Releases Security Updates, Addresses Safari RSS Vulnerability

Apple today released several security-related updates through Software Update and Apple's Support Downloads site.

Security Update 2009-001 addresses a number of vulnerabilities detailed in the update's support document, notably including the Safari RSS vulnerability disclosed in mid-January.

Multiple input validation issues exist in Safari's handling of feed: URLs. The issues allow execution of arbitrary JavaScript in the local security zone. This update addresses the issues through improved handling of embedded JavaScript within feed: URLs. Credit to Clint Ruoho of Laconic Security, Billy Rios of Microsoft, and Brian Mastenbrook for reporting these issues.

The update is available in a number of versions:

- Leopard Universal (43.4 MB)
- Leopard Server Universal (46.54 MB)
- Tiger Intel (164.23 MB)
- Tiger PPC (74 MB)
- Tiger Server Universal (213 MB)
- Tiger Server PPC (141.76 MB)

Apple also released Safari 3.2.2 for Windows to patch the RSS vulnerability for Windows users.

Finally, Apple released Java updates for both Leopard (3 MB) and Tiger (1.6 MB). According to the support documents (Leopard, Tiger), both updates address the same vulnerabilities in the Java plug-in and Java Web Start.

Top Rated Comments

(View all)

39 months ago
Good. I'm glad to see they fixed that RSS issue. :)
Rating: 0 Positives / 0 Negatives
39 months ago
i was just searching the forum to see if that issue has been fixed :)
Rating: 0 Positives / 0 Negatives
39 months ago
Downloading now.

Software REQUIRES a restart.
Rating: 0 Positives / 0 Negatives
39 months ago

Software REQUIRES a restart.


Security updates usually do.
Rating: 0 Positives / 0 Negatives
39 months ago
Good to see this on MR page #1...:)
Rating: 0 Positives / 0 Negatives
39 months ago
Seems like i have an apple remote desktop update as well...Which is strange because I have 3.2.2 already...
Rating: 0 Positives / 0 Negatives
39 months ago
According to ZDNet, there are patches for 48 vulnerabilities in OS X.
Rating: 0 Positives / 0 Negatives
39 months ago
I updated .71 seconds ago. I've experienced no problems since then.
Rating: 0 Positives / 0 Negatives
39 months ago
What version of Safari did the update end at 3.2.1 or 3.2.2? I ran the updates and ended with 3.2.1
Safari refused to quite before the update installed. I forced quite but it stayed as an active task in Activity Monitor. I inspected it and Activity monitor said it did not exist but the memory was never freed up so I was wondering if the update was messed up.
Rating: 0 Positives / 0 Negatives
39 months ago
Bernd, the Safari update is for Windows users only.
Rating: 0 Positives / 0 Negatives

[ Read All Comments ]