Brief Hands-On Report--Apple Security Update 2007-006
The standard version of Security Update 2007-006 has the following security updates:
WebCore--CVE-2007-2401--Visiting a malicious website may allow cross-site requests. An HTTP injection issue exists in XMLHttpRequest when serializing headers into an HTTP request. By enticing a user to visit a maliciously crafted web page, an attacker could conduct cross-site scripting attacks. This update addresses the issue by performing additional validation of header parameters. Credit to Richard Moore of Westpoint Ltd. for reporting this issue.
WebKit--CVE-2007-2399--Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. An invalid type conversion when rendering frame sets could lead to memory corruption. Visiting a maliciously crafted web page may lead to an unexpected application termination or arbitrary code execution. Credit to Rhys Kidd of Westnet for reporting this issue.
The version for Mac OS X 10.4.9 or later with Safari 3 Beta installed includes this additional update to bring the Public Beta to version 3.0.2:
Safari--CVE-2007-2400-Visiting a malicious website may allow cross-site scripting. Safari's security model prevents JavaScript in remote web pages from modifying pages outside of their domain. A race condition in page updating combined with HTTP redirection may allow JavaScript from one page to modify a redirected page. This could allow cookies and pages to be read or arbitrarily modified. This update addresses the issue by correcting access control to window properties. Credit to Lawrence Lai, Stan Switzer, Ed Rowe of Adobe Systems, Inc for reporting this issue.
Similar security fixes and an additional one were released for the Windows version of Safari 3 Beta.
We installed Security Update 2007-006 via Software Update on a variety of Macs: 15" MacBook Pro C2D-LED, 24" iMac C2D, 20" iMac CD, PowerMac G4 Cube and 12" PowerBook G4. We installed Security Update 2007-006 in Safari 3 Beta Update 3.0.2 via Software Update on a PowerMac G4 Cube. All were running Mac OS X 10.4.10. We encountered no problems applying the update nor in limited use thereafter. [Bill Fox & Dana Baggett]
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?