Apple issues 11 security updates for Safari browser

The Safari 3.2 update addresses multiple vulnerabilities and adds a new anti-phishing and anti-malware feature.

Apple on Thursday released Safari 3.2, with 11 security updates for Mac OS X and Windows, to close up multiple vulnerabilities, some of which could lead to remote code execution.

The updates are available for Windows XP or Vista, Mac OS X v10.4.11 and Mac OS X v10.5.5. Eight of the updates are specific to Safari and three are specific to WebKit, an open-source application framework.

The patched vulnerabilities could allow an attacker to execute arbitrary code, cause unexpected application termination, foster a denial-of-service condition or obtain sensitive information. The vulnerabilities can be exploited through a maliciously crafted JPEG or TFF image, website or HTML page, Apple said in an advisory.

US-CERT, in an email alert Friday, said they encourage users to review Apple Article HT3298 and apply any necessary updates. 

Safari version 3.2 also includes anti-phishing and anti-malware protection, which Apple calls “fraudulent site” protection that displays an alert when a possible phishing site is detected, Mac security software company Intego said in a blog post Friday. 

Users will be alerted to suspicious malware and phishing sites on Safari 3.2.

"It's a pretty big step for Apple to finally say loud and clear that yes, there are security issues we need to deal with," Intego spokesman Peter James told SCMagazineUS.com Friday. "Everyone's at risk for phishing, which is a pretty serious problem.”

Earlier this week, Apple issued an update to its iLife suite of multimedia software programs, correcting three vulnerabilities that could be exploited to crash an application or execute remote code.

See original article on scmagazineus.com
Copyright © SC Magazine, US edition

What are your thoughts on this article? Add your comment below.

To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.

NOTE: You must be a registered member of SC Magazine to post a comment.

Click here to login | Click here to register
comments powered by Disqus
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read