Brief Hands-On Report--Apple released Safari 3 Beta Update 3.0.3
Safari Beta 3.0.3 is recommended for all users and improves its security and stability.
Here are the details of the security fixes for Mac OS X 10.4.9 or later:
WebKit--CVE-2007-2408--Visiting a malicious website may allow Java applets to load and run even when Java is disabled. Safari provides an "Enable Java" preference, which when unchecked should prevent the loading of Java applets. By default, Java applets are allowed to be loaded. Navigating to a maliciously crafted web page may allow a Java applet to be loaded without checking the preference. This update addresses the issue through a stricter check of the "Enable Java" preference. Credit to Rhys Kidd and Scott Wilde for reporting this issue.
WebKit--CVE-2007-3742--Look-alike characters in a URL could be used to masquerade a website. The International Domain Name (IDN) support and Unicode fonts embedded in Safari could be used to create a URL which contains look-alike characters. These could be used in a malicious web site to direct the user to a spoofed site that visually appears to be a legitimate domain. This update addresses the issue by through an improved domain name validity check. Credit to Tomohito Yoshino of Business Architects Inc. for reporting this issue.
WebKit--CVE-2007-3944--Viewing a maliciously crafted web page may lead to arbitrary code execution. Heap buffer overflows exist in the Perl Compatible Regular Expressions (PCRE) library used by the JavaScript engine in Safari. By enticing a user to visit a maliciously crafted web page, an attacker may trigger the issues, which may lead to arbitrary code execution. This update addresses the issues by performing additional validation of JavaScript regular expressions. Credit to Charlie Miller and Jake Honoroff of Independent Security Evaluators for reporting these issues.
We downloaded and installed Safari 3.0.3 via Software Update on a number of Macs, including MacBook Pro C2D, iMac CD and PowerMac G4 Cube. All went well. We haven't noticed any particular bugs in 3.0.2 and so far we've not seen one in 3.0.3. [Bill Fox & Dana Baggett]
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?