Brief Hands-On Report--Apple released iPhone Software 1.0.1

Apple released iPhone Software 1.0.1 and it is available for download and installation via iTunes when your iPhone is connected to your Mac and iTunes is open. According to the ReadMe file,

This version of the software includes bug fixes and supercedes all previous versions.

Not very illuminating but here are the details of the security fixes from our other Apple sources:

Safari--CVE-2007-2400--Visiting a malicious website may allow cross-site scripting. Safari's security model prevents JavaScript in remote web pages from modifying pages outside of their domain. A race condition in page updating combined with HTTP redirection may allow JavaScript from one page to modify a redirected page. This could allow cookies and pages to be read or arbitrarily modified. This update addresses the issue by correcting access control to window properties. Credit to Lawrence Lai, Stan Switzer, and Ed Rowe of Adobe Systems, Inc. for reporting this issue.

Safari--CVE-2007-3944--Viewing a maliciously crafted web page may lead to arbitrary code execution. Heap buffer overflows exist in the Perl Compatible Regular Expressions (PCRE) library used by the JavaScript engine in Safari. By enticing a user to visit a maliciously crafted web page, an attacker may trigger the issues, which may lead to arbitrary code execution. This update addresses the issues by performing additional validation of JavaScript regular expressions. Credit to Charlie Miller and Jake Honoroff of Independent Security Evaluators for reporting these issues.

WebCore--CVE-2007-2401--Visiting a malicious website may allow cross-site requests. An HTTP injection issue exists in XMLHttpRequest when serializing headers into an HTTP request. By enticing a user to visit a maliciously crafted web page, an attacker could trigger a cross-site scripting issue. This update addresses the issue by performing additional validation of header parameters. Credit to Richard Moore of Westpoint Ltd. for reporting this issue.

WebKit--CVE-2007-3742--Look-alike characters in a URL could be used to masquerade a website. The International Domain Name (IDN) support and Unicode fonts embedded in Safari could be used to create a URL which contains look-alike characters. These could be used in a malicious web site to direct the user to a spoofed site that visually appears to be a legitimate domain. This update addresses the issue by through an improved domain name validity check. Credit to Tomohito Yoshino of Business Architects Inc. for reporting this issue.

WebKit--CVE-2007-2399--Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. An invalid type conversion when rendering frame sets could lead to memory corruption. Visiting a maliciously crafted web page may lead to an unexpected application termination or arbitrary code execution. Credit to Rhys Kidd for reporting this issue.

At first, iTunes said our software was up to date so we clicked the "Check for Update" button and then the availability of the new update v1.0.1 was revealed. We clicked the Update button and the words "Software Update" appeared on our iPhone's screen, followed by an Apple logo and progress bar. It took several minutes to complete updating the iPhone software/firmware. Then the updated iPhone software was verified, the iPhone restarted and beeped when it was done.

After the update, one thing we noticed right off is that the slider controls and On/Off buttons are much more responsive and work very well. [Bill Fox]

Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Reviews · This month in the archive