• On The Insider: Bruno Film Edited Due to Jackson's Death
June 14, 2007 3:07 PM PDT

Another flaw within Safari 3.0 for Windows beta

by Robert Vamosi

Security researcher Robert Swiecki disclosed yesterday another vulnerability within the new Safari 3.0 for Windows beta, bringing the total of public vulnerabilities to nine. The latest flaw allows an attacker to steal a cookie. The flaw exists in the Javascript's window.setTimeout()implementation where the content timer-triggered function is processed after window.location property is changed.

In response to other Safari 3.0 vulnerabilities, Apple today released an updated version that addresses three of the nine public vulnerabilities.

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
Recent posts from News Blog
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission
Was InfoWorld's CTO of the Year award a year late?
VMWare VI4 renamed to vSphere
Add a Comment (Log in or register) (3 Comments)
  • prev
  • 1
  • next
B-E-T-A
by MadKiwi June 14, 2007 4:33 PM PDT
While it is disappointing to see so many apparent flaws appearing so quickly remember this is BETA software. Anyone stupid enough to replace their current browser with ANY beta software and then use for all their everyday browsing deserves what they get.

Safari 3 beta is NOT ready for prime time. As well as the security issues it crashes when trying to authenticate to a proxy server and, in my case, fails to load pages on our protected intranet.

I look forward to Apple getting Safari right as it has some really nice features but in the mean time it will NOT be anything but a test piece of software for me.

Finally, IMHO, this is turning out to be somewhat of a PR disaster for Apple...
Reply to this comment
BAY TUH!
by MaLvaDo39 June 14, 2007 7:08 PM PDT
Crazy people! Of course BETA is not ready for prime time.

Stop trying to use it as your main browser and expect it to be a
release version.

Any publicity is good publicity especially the day when the news
comes through saying Safari is ready for full release.
Safari 3.0.1 Beta fixes FIVE of the vulnerabilities
by TheBugsAttack June 14, 2007 5:15 PM PDT
The version released today (3.0.1 Beta) addresses five of the
(now) nine vulnerabilities, not three as the article incorrectly
states:

http://www.rec-sec.co.il/2007/06/12/apple-safari-for-
windows-vulnerabilities/

Look at the end of the page for the five fixed and three of the
(yet) un-fixed vulnerabilities.
Reply to this comment
(3 Comments)
  • prev
  • 1
  • next
advertisement

Can RIM get its mojo back?

The new BlackBerry Tour, carried by Verizon and Sprint, arrives Sunday, even as RIM seems to be losing sales to exclusive devices like the iPhone and Pre.

With Chrome, Google reignites the OS wars

roundup Google Chrome OS, due in 2010, underscores the Web giant's cloud-computing ambitions and opens new competition with Microsoft.
• What Chrome OS has on Windows that Linux doesn't

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right