Apple Patches WebCore, Safari 3.0 Beta, and WebKit
Security Update 2007-006
This update fixes a HTTP injection issue that comes from WebCore’s XMLHttpRequest when serializing headers into an HTTP request. Apple stated that a user could visit a malicious website and an attacker could conduct cross-site scripting attacks. The update performs additional validations of header parameters. The update also fixes an invalid type conversion that occurs when WebKit renders frame sets, which could lead to memory corruption.
Safari 3 Beta Update 3.0.2
Apple also released a patch to their recently released Safari 3 on both Macs and PC. Of course the first thing fixed was a Windows only bug that allowed a web page to dynamically change the contents of the address bar without loading the contents of the corresponding page. The other fix, which applies to both Mac and Windows users, fixes a race condition in page updating. Apple stated, “This could allow cookies and pages to be read or arbitrarily modified.”
Popularity: 4%
Filed Under Apple, Updates, WebCore, WebKit | dillon | Leave a Comment
