Hand-On Report--Safari 3.1.1

Apple released Safari 3.1.1 and it is available via Software Update or as a stand-alone file from this Apple Web page. According to Apple,

This update is recommended for all Safari users and includes improvements to stability, compatibility and security.

The explanation is as vague as usual but Apple posted the details of the security fixes for Mac OS X 10.5.2 and 10.4.11, client and server editions, which are:

WebKit--CVE-2008-1025--An issue exists in WebKit's handling of URLs containing a colon character in the host name. Opening a maliciously crafted URL may lead to a cross-site scripting attack. This update addresses the issue through improved handling of URLs. Credit to Robert Swiecki of the Google Security Team, and David Bloom for reporting this issue.

WebKit--CVE-2008-1026--A heap buffer overflow exists in WebKit's handling of JavaScript regular expressions. The issue may be triggered via JavaScript when processing regular expressions with large, nested repetition counts. This may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation of JavaScript regular expressions. Credit to Charlie Miller working with TippingPoint's Zero Day Initiative for reporting this issue.

I downloaded and installed Safari 3.1.1 via Software Update. No problems were encountered in several hours use. [Bill Fox]

Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Mac OS · This month in the archive