Skip Navigation

  • Home
  • Contact us
  • FAQ
  • Glossary
  • Public key
  • Sitemap
  • Cymraeg
  • What's new
CPNI - Centre for the Protection of National Infastructure

Advanced search

  • About CPNI
  • The threats
  • Security planning
  • Methods of attack
  • Protecting your assets
  • Products and services
    • CSIRTUK advisories
      • Advisories archive
    • General protective security publications
    • InfoSec briefings
    • InfoSec technical notes
    • InfoSec vulnerability disclosures
    • Good practice guidelines
    • Viewpoints
    • Information exchanges
    • Risk Management Delivery Group
  • Research
Home > Products and services > CSIRTUK advisories > Advisories archive > June 2008 > 3644 - APPLE-Security Advisory describing the release of Safari v3.1.2 for Windows

June 2008

3644 - APPLE-Security Advisory describing the release of Safari v3.1.2 for Windows

ID: 3644
Date: 20/06/2008

Title: 3644 - APPLE-Security Advisory describing the release of Safari v3.1.2 for Windows
Platform level affected:Net Application - Client
Hardware components affected:Apple MAC
Specific operating systems components affected: Apple Mac OS
Net-enabled software: Enterprise Application
Other software: Web Browser
Remediation Summary:Update your copy of the software with the download available from the supplier.
Vendors affected:Aplle
Applications affected:Safari for Windows
Adversity source: Unknown
Attack Vector: Vulnerability exploitation
Virulence: Unknown
Warning Status: Unknown
Potential Damage: Remote execution/modification
Possible Duration: Unknown
Availability of fix: Available
Type of fix: Patch
Source: http://support.apple.com/kb/HT1222
Reliability of source: Trusted
Source URL: http://support.apple.com/kb/HT2092
CVE: CVE-2008-1573; CVE-2008-2540; CVE-2008-2306; CVE-2008-2307
Abstract: Details of Safari v3.1.2 for Windows released by Apple that addresses a number of security issues.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

APPLE-SA-2008-06-19 Safari v3.1.2 for Windows

Safari v3.1.2 for Windows is now available and addresses the following issues:

Safari
CVE-ID:  CVE-2008-1573
Available for:  Windows XP or Vista
Impact:  Viewing a maliciously crafted BMP or GIF image may lead to information disclosure
Description:  An out-of-bounds memory read may occur in the handling of BMP and GIF images, which may lead to the disclosure of memory contents. This update addresses the issue by performing additional validation of BMP and GIF images. This issue is addressed in systems running Mac OS X v10.5.3, and in Mac OS X v10.4.11 with Security Update 2008-003. Credit to Gynvael Coldwind of Hispasec for reporting this issue.

Safari
CVE-ID:  CVE-2008-2540
Available for:  Windows XP or Vista
Impact:  Saving untrusted files to the Windows desktop may lead to the execution of arbitrary code
Description:  An issue exists in how the Windows desktop handles executables. Saving an untrusted file to the Windows desktop may trigger the issue, and lead to the execution of arbitrary code. Web browsers are a means by which files may be saved to the desktop. To help mitigate this issue, the Safari browser has been updated to prompt the user prior to saving a download file. Also, the default download location is changed to the user's Downloads folder on Windows Vista, and to the user's Documents folder on Windows XP. This issue does not exist on systems running Mac OS X. Additional information is available from http://www.microsoft.com/technet/security/advisory/953818.mspx which credits Aviv Raff with reporting the issue.

Safari
CVE-ID:  CVE-2008-2306
Available for:  Windows XP or Vista
Impact:  Visiting a malicious website which is in a trusted Internet Explorer zone may lead to the automatic execution of arbitrary code
Description:  If a website is in an Internet Explorer 7 zone with the "Launching applications and unsafe files" setting set to "Enable", or if a website is in the Internet Explorer 6 "Local intranet" or "Trusted sites" zone, Safari will automatically launch executable files that are downloaded from the site. This update addresses the issue by not automatically launching downloaded executable files, and by prompting the user before downloading a file if the "always prompt" setting is enabled. This issue does not exist on systems running Mac OS X. Credit to Will Dormann of CERT/CC for reporting this issue.

WebKit
CVE-ID:  CVE-2008-2307
Available for:  Windows XP or Vista
Impact:  Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution
Description:  A memory corruption issue exists in WebKit's handling of JavaScript arrays. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.
This update addresses the issue through improved bounds checking.
Credit to James Urquhart for reporting this issue.

Safari v3.1.2 for Windows is available via the Apple Software Update application, or Apple's Safari download site at:
http://www.apple.com/safari/download/

Safari for Windows XP or Vista
The download file is named:  "SafariSetup.exe"
Its SHA-1 digest is:  c63db818658532d3ff2762378b0b7b7e6aace0d6

Safari+QuickTime for Windows XP or Vista
The file is named:  "SafariQuickTimeSetup.exe"
Its SHA-1 digest is:  22ebca0a88b5814e22f015daea1be27489e6e7be

Information will also be posted to the Apple Security Updates web site:  http://support.apple.com/kb/HT1222

This message is signed with Apple's Product Security PGP key, and details are available at:
http://www.apple.com/support/security/pgp/

-----BEGIN PGP SIGNATURE-----
Version: 9.7.2.1608

wsBVAwUBSFqRZHkodeiKZIkBAQgxiAf9HapNeskNLM++Bjfc3T37jpGOe1LRPdMc
GNuCnUIrHzVcr5ZenYRwndz1LtH0Ui6kCo7sazGYAbqEZjNmFUusdByOIo6KikKf
ejntmZsgRGLh7qlTOCwBO/9DptAfrGWQZMqhES1u/enfKjBgg/2ijq/DZhhBlTrA
QQBp6xtDk8aIiIui8UdYFSauyoSOAuomaHTtMU2Wis6h2hHE8rmwG9/9TRZo5Woc
SkzeDi0pjxpyCrEQ3LARBxMd3eEaZx/+2PQeY30m3VKKpenUuj+G7D7Ejz+Uu7Nk
ej6u3zdHmnHAcoAE9gmOPxKCZ0XemzuULzi824EN+aLkqHz0CgWNSg==
=iDKS
-----END PGP SIGNATURE-----


 

This advisory contains information released by the original author. Some of the information may have changed since it was released. If the issue affects you, it may be prudent to retrieve the advisory from the site of the original source to ensure that you receive the most current information concerning that problem. Reference to any specific commercial product, process, or service by trade name, trademark manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favouring by CPNI.

The views and opinions of authors expressed within this notice shall not be used for advertising or product endorsement purposes. CPNI shall not accept responsibility for any errors or omissions contained within this advisory. In particular, they shall not be liable for any loss or damage whatsoever, arising from or in connection with the usage of information contained within this advisory.

CSIRTUK is a member of the Forum of Incident Response and Security Teams (FIRST) and has contacts with other international Incident Response Teams (IRTs) in order to foster cooperation and coordination in incident prevention, to prompt rapid reaction to incidents, and to promote information sharing amongst its members and the community at large.

Fri, 20 Jun 2008 10:26:00 GMT
Domain affected: Technical
  • Accessibility |
  • Terms and conditions |
  • Privacy statement |
  • Data protection act |
  • Freedom of information |