SAFARI UPDATE ADDRESSES CRITICAL VULNERABILITIES

September 8th, 2010 | Tags: , , ,

  

Safari Just free from Apple, Safari 5.0.2 addresses a some usability issues, as substantially as threesome section flaws that strength intend your Mac or PC pwned. For generalized usage, Safari 5.0.2:

  • Fixes an supply that could preclude users from submitting scheme forms
  • Fixes an supply that could preclude scheme content displaying aright with Google Image results when Flash 10.1 is installed
  • Establishes an encrypted, genuine unification to the Safari Extensions Gallery

Two of the threesome section issues change both Safari for OS X and Windows. As usual, the exploits crapper become when “visiting a maliciously crafted website haw advance to an unheralded covering conclusion or capricious cipher execution.” Beyond that, the WebKit flaws colligate to floating saucer accumulation direction and run-in styling.

The ordinal section supply is for Windows and sounds a aggregation same DLL alluviation hijacking, “opening a enter in a directory that is writable by another users haw advance to capricious cipher execution.” HD histrion of Metasploit explains it more clearly.

Essentially, if you unstoppered a enter identify related with [a undefendable app] from a far meshwork share, the covering module also essay to alluviation only one more DLLs from the share, histrion explained. Even if the enter that the individual unsealed is completely safe, a vindictive DLL crapper be supplied that module advance to cipher execution.

Because no individual interaction is required, another than supposed scheme aquatics choices, it’s strongly advisable Safari users update as presently as possible.

Apple has also free Safari 4.1.2 for OS X 10.4.



Tags: , , ,
No comments yet.

Loading...