Apple patches security holes in Safari browser
Thursday, November 12, 2009
Yesterday, Cupertino, California-based computer company Apple released version 4.0.4 of Safari, its web browser available for Mac, PC, and iPhone operating systems.
The update plugs what are thought to be moderate-to-serious security flaws in the browser, though CNET News notes that Apple does not rate the severity of vulnerabilities like Microsoft and Google. PC Magazine writes that two out of the seven flaws addressed are capable of remote code execution, the prerequisite for malicious takeovers of malware-infected PCs.
Malicious XML, FTP and image content can be crafted to crash or exploit Windows and Mac versions of Safari, in addition to causing unpredictable network security threats when visiting other websites. Only Windows versions of Safari are susceptible to the embedded image color profile trick, while an exploit that could allow email to remotely access audio and video content affects Macs only.
The patch comes amid a rare uptick in security news about Apple products, with a pair of iPhone worms hitting the network and a large-scale patch for the company's operating systems making headlines over the past several days.
Related News:
Small businesses need stronger web security - 3.11.2010 Cyber criminals have increased efforts to target the bank accounts of small businesses because they frequently do not have the web security measures in place that larger companies do, according to David Nelson of the Federal Deposit Insurance Corporation.
UK bankers struggle with online fraud - 3.11.2010 Online banking fraud cost bankers in the UK the equivalent of nearly $90 million in 2009, according business technology website Silicon.com.
Koobface changes as web security professionals prepare attack - 3.11.2010 As web security professionals attempt to take down Koobface, the cyber criminals that designed the malware strain have altered the virus to escape potential elimination, according the Register, a technology news website based in the UK.
Cyber criminals target web security with phony Windows update - 3.11.2010 As more people update from Windows Vista or Windows XP, cyber criminals have developed malware that takes advantage of people's desire to make the move, according to Computer Weekly.
Botnet activity diminished following ISP failure - 3.11.2010 The shutdown of internet service provider Troyak.org, a company based in Kazakhstan, resulted in the diminution of Zeus botnets on the web on Tuesday, according to Swiss web security blog Abuse.ch.
|