NEW YORK, 1:53 PM, FRI MAY 16 | 56 POSTS IN THE LAST 24 HOURS | tips@gizmodo.com | SUBMIT A TIP | RSS
UK | FR | NL | IT | DE | ES | JP | AU

Apple Issues Windows Safari Update

Those of you who downloaded the the Windows Safari 3.0 beta earlier this week should head on over to the download site and grab the new 3.0.1. Or even easier, just use the auto-updater included with Safari. It patches a number of security holes found this week (listed after the jump), and should probably be installed as quickly as possible. This is only for Windows, btw. Macs don't have those problems. (Typical.)

Download Page [Apple]

The Safari 3 Public Beta was released on June 11 for Mac OS X and Windows XP/Vista. This beta software is for trial purposes and intended to gather feedback prior to a full release. As with all our products, we encourage security researchers to report issues to product-security@apple.com.

Safari 3.0.1 Public Beta for Windows is now available and addresses
the following issues in Safari 3 Public Beta:

CVE-ID: CVE-2007-3186
Available for: Windows XP or Vista
Impact: Visiting a malicious website may lead to arbitrary code
execution
Description: A command injection vulnerability exists in the Windows
version of Safari 3 Public Beta. By enticing a user to visit a
maliciously crafted web page, an attacker can trigger the issue which
may lead to arbitrary code execution. This update addresses the
issue by performing additional processing and validation of URLs.
This does not pose a security issue on Mac OS X systems, but could
lead to an unexpected termination of the Safari browser.

CVE-ID: CVE-2007-3185
Available for: Windows XP or Vista
Impact: Visiting a malicious website may lead to an unexpected
application termination or arbitrary code execution
Description: An out-of-bounds memory read issue in Safari 3 Public
Beta for Windows may lead to an unexpected application termination or
arbitrary code execution when visiting a malicious website. This
issue does not affect Mac OS X systems.

CVE-ID: CVE-2007-2391
Available for: Windows XP or Vista
Impact: Visiting a malicious website may allow cross-site scripting
Description: A race condition in Safari 3 Public Beta for Windows
may allow cross site scripting. Visiting a maliciously crafted web
page may allow access to JavaScript objects or the execution of
arbitrary JavaScript in the context of another web page. This issue
does not affect Mac OS X systems.

The update is available via the "Apple Software Update" application,
which is installed with the most recent version of QuickTime or
iTunes on Windows.

Safari 3.0.1 Public Beta for Windows is also available via Apple's
Safari download site at: http://www.apple.com/safari/download/

Safari for Windows XP or Vista
The download file is named: "SafariSetup.exe"
Its SHA-1 digest is: e468f56613abaa3afd692ded78c35eaf109ca0b6

Safari+QuickTime for Windows XP or Vista
The download file is named: "SafariQuickTimeSetup.exe"
Its SHA-1 digest is: af73dd81793b2802200da5d7d5c8077a67ca57ec

This message is signed with Apple's Product Security PGP key,
and details are available at:
http://www.apple.com/support/security/pgp/

12:09 PM on Thu Jun 14 2007
By Jason Chen
5,401 views
36 comments

Comments

  • Will it stop all the bitching from people who had no intention of using it in place of FireFox, but feel the need to whine anyway? Maybe that's planned for the Final Release.

  • +1

  • and I still have no idea wtf is up with that image

  • Wow that was really fast for an update.

    Props to Apple for quick reaction.

  • Props to Apple for such a quick fix.

  • Image of Pope John Peeps II Pope John Peeps II at 12:21 PM on 06/14/07 *

    Description: A race condition in Safari 3 Public Beta for Windows may allow cross site scripting.

    Oh Doctor Martin Luther King, where are you now in our HOUR OF NEED?!

  • Props for quickness?! All that the quick turnaround on these bugs tells me is, if the errors were that easy to find and fix after someone bumped into them, that Apple's own QA on this project is either asleep or non-existent (indeed, why waste time testing something that is intended for Windows?).

  • Wow, that was quick. Never seen that kind of speed out of Redmond. Could these patches have already been in the pipeline?

  • no thanks, I uninstalled that piece of crap!!!

  • Just use the handy Apple Software Update app for Windows...

  • can you say rushed beta release?

  • If someone was able to find bugs within 2 hours of the release, it obviously wasn't tested. 18 bugs in 2 days? None of the Safari 2.0 advisories on Secunia have even been addressed yet.

    Instead of the "Apple Software Update app," use the even handier "Add/Remove Programs" section and choose "Safari" as the option.

  • They say it's faster, but in actuality, it's about 10X slower than firefox or IE on my PC.

  • @ Architeuthis

    ok, if Apple releases patches quickly, their QA sucks? If they release patches slowly, they suck? So because they release a F#cking BETA piece of software for an app running on non-native OS, and they react quickly to bug reports, you slam them?

    So whats MicroSofts excuse? They Have way more bugs on apps written by them for their OWN OS and take WAY longer to release fixes. Stop being a hater just because its Apple.

  • I could go for for an update to the Mac version. I had to uninstall it because it was giving me erros with iChat. Another friend of mine (an Apple rep no less) was having the same issue.

  • @d_saum

    Stop being a mindless Apple defender.

    Ohh I love fanboy warz

  • It still shows absolutely no text on my PC. No menus and no text inside pages.

  • I downloaded this to give it a try and it's way slower than IE7.

    YOU CAN'T EVEN SORT YOUR BOOKMARKS WITHOUT A THIRD PARTY APPLICATION?

    I'll try it out for the rest of the day but I'll stick with IE7 because it's pretty and I can acutally Right Click > Sort

  • wow pc drones are out in full force today

  • I know I'm being all conspiracy theory, but I wouldn't put it past apple to make it buggy on purpose just so they can turn around and patch it fast and look all cool. That whole company exists on PR.

  • @ clemonator

    Im not being a mindless Apple defender. If you have gripes with Apple products, thats fine, and there are a bunch of legitimate complaints here, but dont be an asshat because they got patches out quickly on a beta. Thats all I'm saying.

  • Architeuthis: Evidently you don't know how to code. After reading Larholm's report of the protocol bug, for example, the solution is extremely simple (sanitize a string before passing it to a method). However, finding the bug (figuring out that non-standard protocols in urls on iframes has invalid sanitizing) was the difficult part in this case, as it's nothing that would /ever/ show up on a normal web site.

    I say, surprisingly fast update. Nice work.

    (However, it's still very very buggy, which is not-as-nice-work. All bold text is invisible on my Win machine.)

  • I uninstalled it from my MBP and my XP machine at work.
    I enjoy using Safari on my MBP; but I don't mean to "f" around with this Beta.

  • Wow, that was quick. Never seen that kind of speed out of Redmond.

    That is because every patch released for an MS product goes through a full battery of regression and security testing these days. A patch that fixes one problem but causes five more is not worth releasing. I suspect what apple is doing is using the beta status of this product as a way of skipping proper QA process and having customers do the work for them.

    So whats MicroSofts excuse? They Have way more bugs on apps written by them for their OWN OS and take WAY longer to release fixes.

    Uh, like apple fixing 0 day exploits released in the MoAB several months later, in freaking April? Or the fact that they have patched 100+ security vulnerabilities in their own OS since january, at roughly 4 to 1 the rate that Vista has needed patching in terms of security? Get off it. Apple takes their time on patching released software just like MS, because you *should* thoroughly test any release patch. They are taking a shortcut here because of the beta status and the frankly abismal release quality to begin with.
  • This is only for Windows, btw. Macs don't have those problems. (Typical.)

    Classic Apple fanboy nonsense. Apple is somehow deemed superior even when they release a product that has a major flaw on Windows but not on their own OS/hardware.

    Typical indeed.

  • Of course I don't know how to code. I've only been doing it professionally for 20 years.

    If you guys noticed, I've said nothing against Apple developers. For all I know, they are the greatest bunch of guys alive. But "it only shows up on a weird site" is as lame an excuse for lack of proper testing as they come. This is precisely the purpose of QA - to seek out, or invent if necessary, the weird cases, and test for them; whereas successfully charting a narrow code execution path so that nothing bad happens to your app is not it.

  • The best bang for the buck hands down are PC's. They are the only way to go in my opinon. I can get a relatively cheap computer from a variety of manufactures or I can custom build my own. Mac users are only limited by what Apple offers(Isheep). Being in the bay area I notice most Apple users are hippy granola crunchers or art school students in San Francisco trying to sell some political idea or change the world. My PC friends play (new)games with each other over networks, exchange illegal and pirated software, swap out disc drives and video cards with parts you can buy at a local electronic store, also worthy to note my PC friends do not dress like hippys and do not have political causes. Yes I might be stereotypical but I have lived in the Bay Area for 24 years. I notice apple users have the same SMUG attitude, like their shit doesn't stink. Much like a Prius drver.... Sorry for my rant but I hate Apple and I can not stand Steve Jobs. Thanks to all the loopy liberals that ruined San Francisco too.

  • When will the PC hating stop.....

  • Wow, that was quick. Never seen that kind of speed out of Redmond. Could these patches have already been in the pipeline?

    Uh, Microsoft had a 3 day turnaround when their Windows Media DRM was cracked. Remember FairUse4WM? Stopped working after Microsoft updated their DRM code. It's a cat and mouse game, and most of the time, it only lasts for around a month before Microsoft pushes another DRM update.

    As for PCs vs Macs - well, most people buy Dells and HPs, and they just pick whatever's in their lineup. Very few people build their own PC anymore - the cost-effectiveness isn't there. The only advantage to building your own nowadays is so you can get the latest ATi or nVidia 2903587095874520409999 SUPER XXXTREME card with 3902TB of memory on it. The rest of us seem to just buy Apple, HP, or Dell, or whatever.

    (I use a Mac Pro running XP. It cost less than the equivalent Dell (and DIY was maybe a few bucks cheaper... but then I had to f ind a case that was quiet(... when you could find it - stupid Intel. "Xeon" can refer to a Pentium 4 HT or the Core2 version, making it hard to compare since you likely picked the Pentium 4 instead of the Core2... Still haven't found anything that can load down 2x dual core...).

  • That picture is so incredibly tacky. Out of hundreds of thousands of options on the intertubes, you can come up with something better.

  • @Architeuthis
    Ahem. I actually misread your post. I apologize.

  • Wow. That Mac rant was intense. I'm a PC user, but there's not a day that I don't believe the Mac is better. The points about customizing your own equipment and swapping drives, games, etc. are all fine and they've been made before. No need to get personal or angry about it. They're not all granola-crunching hippies, they just prefer a better product. People buy a more expensive car because it might have less problems, is more fun to drive and is built to be safer. This Mac/Pc debate will go on for as long as Bill and Steve remain alive. I de-installed Safari, not because it was slow or a lesser product on the PC but because Firefox is just so good, with add-ons, themes, and it's fast. Also, the iSafari theme is a nice touch. I'll re-install Safari when iPod 6g comes out. I have a feeling that iTunes, Safari and iPod will need to work together.

  • fuck you all I'm off to buy a Sun Ultra :)

  • @redredred

    Just a suggestion, but instead of whining about bugs in these comments where nobody cares, why not make use of that handy Report Bugs menu item in Safari? You can even add it to your toolbar (right click on toolbar --> Customize toolbar...). It's a winning situation for everybody: Apple hears about the bug and it gets fixed, and the rest of us don't have to listen to you cry about it.

  • cybergrunt says:

    fuck you all I'm off to buy a Sun Ultra :)

    My Amiga is sooo much better than your Sun. You're such a Sun fanboy, everyone knows Amiga's are 100000x's more secure.
  • @JakeSlatnesky

    You almost had me there buddy! Nicely done - I actually started to believe you really thought Mac's were better machines. But alas I read your post for what it was - more fodder for fanboy flame wars. Brill I say, just brill!

    Surely no one could be so ignorant(I too have fodder!) to believe that a multinational corporation like Apple is any different from one like HP or Dell - they want your $$$. Mac's are more expensive because they advertise more than any other company on this planet (should be noted that the quality of their advertising is not only a joy to behold but also far superior to any product they have ever carried).

    Interestingly however their advertising is only partially aimed at the switch campaign. The rest is firmly aimed at the religious zealots who line up for new ipods every two weeks. These advertisements are meant to buoy the self esteem of those who fall prey to the marketing campaigns of 'His Steveness' (who is a genius). Rather than exercise their freedom of choice, in an inherently consumerist society, they proudly pile all their eggs into the proverbial Apple basket. Are you the same people who all drive Fords as well? I am proud to have owned an iMac (noisy and constantly crashing with OS 9 and still runs), my own hand built PC (noisy as hell but rock solid with win2K), a Toshiba (best laptop I ever owned), a Vaio (peice of crap in every sense), and next week my new ASUS G1S. I was looking at the new MBP 15 inch but couldn't justify the extra $800 for IDENTICAL hardware. The $900 to add an extra 2 GB's of RAM is also laughable (clearly a company that believes in value for it's loyal fanatics). I also find it interesting that such a superior product only comes with 1 year warranty versus my Asus that has 2 out of the box. My G1 also has Lightscribe, HDMI and a VGA on top of my DVI. Did I mention that I get a 4 in 1 card reader? I digress..... The Macbook does have style over substance I will give it that.

    Go Safari on Windows and bring on the iPhone - it's about time someone started bringing in some style to the cell phone market.

    PS Here are links to:

    Memory Express where I am purchasing my G1S
    [www.memoryexpress.com]

    and Apple.ca where I would have purchased the 15 incg MBP.
    [store.apple.com]

Start a discussion:

Reply by Email

Login with your username and password below. Or comment on this post via email.