Brief Hands-On Report--Apple Security Update 2007-006

Apple released Security Update 2007-006 in two versions depending on whether or not Safari 3 Public Beta is installed. The correct version should appear for download via Software Update. This update is for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.9 or later, Mac OS X Server v10.4.9 or later and Intel-based and PowerPC-based Macs.

The standard version of Security Update 2007-006 has the following security updates:

WebCore--CVE-2007-2401--Visiting a malicious website may allow cross-site requests. An HTTP injection issue exists in XMLHttpRequest when serializing headers into an HTTP request. By enticing a user to visit a maliciously crafted web page, an attacker could conduct cross-site scripting attacks. This update addresses the issue by performing additional validation of header parameters. Credit to Richard Moore of Westpoint Ltd. for reporting this issue.

WebKit--CVE-2007-2399--Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. An invalid type conversion when rendering frame sets could lead to memory corruption. Visiting a maliciously crafted web page may lead to an unexpected application termination or arbitrary code execution. Credit to Rhys Kidd of Westnet for reporting this issue.

The version for Mac OS X 10.4.9 or later with Safari 3 Beta installed includes this additional update to bring the Public Beta to version 3.0.2:

Safari--CVE-2007-2400-Visiting a malicious website may allow cross-site scripting. Safari's security model prevents JavaScript in remote web pages from modifying pages outside of their domain. A race condition in page updating combined with HTTP redirection may allow JavaScript from one page to modify a redirected page. This could allow cookies and pages to be read or arbitrarily modified. This update addresses the issue by correcting access control to window properties. Credit to Lawrence Lai, Stan Switzer, Ed Rowe of Adobe Systems, Inc for reporting this issue.

Similar security fixes and an additional one were released for the Windows version of Safari 3 Beta.

We installed Security Update 2007-006 via Software Update on a variety of Macs: 15" MacBook Pro C2D-LED, 24" iMac C2D, 20" iMac CD, PowerMac G4 Cube and 12" PowerBook G4. We installed Security Update 2007-006 in Safari 3 Beta Update 3.0.2 via Software Update on a PowerMac G4 Cube. All were running Mac OS X 10.4.10. We encountered no problems applying the update nor in limited use thereafter. [Bill Fox & Dana Baggett]

Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Security · This month in the archive