Neoseeker : News : Six security vulnerabilities found in Safari 3.0 beta
Hardware Newsletter:
Email:

Latest News
Tue, Nov 18
Mon, Nov 17
Sun, Nov 16
Sat, Nov 15
Fri, Nov 14
Thu, Nov 13

send article hardware newsletter   article comments (6)

Six security vulnerabilities found in Safari 3.0 beta
Kevin Spiess - Tuesday, June 12th, 2007 | 2:44PM (PT)


Safari not in the wild for an entire day before multiple vulnerabilities are found

Right on the download page for Safari, Apple states they designed their new browser to be "secure from day one" -- but what about day zero? It seems that within the first day of Safari's release into the Internet jungle, six security vulnerabilities have been found. The vulnerabilities -- including DoS (Denial of Service), memory corruption, and remote code execution bugs --  were discovered by security experts Aviv Raff, David Maynor, and Thor Larholm, and posted on their respective blogs.

Thor Larholm claims that within 2 hours of use, he located a "fully functional command execution vulnerability", while Aviv Raff says that within a moments of using Hamachi (a community-developed utility for verifying browser integrity) he was able to find a potentially exploitable memory corruption problem. Finding holes in the defenses of Apple's software is not a new hobby taken up by Aviv Raff -- previously,  he worked on the "Month of Apple bugs", which was a publishing of information outlying multiple vulnerabilities in Apple software.  

Although this is only a beta release of Safari 3, this security discoveries may give second thoughts to some of security-conscientious of the PC user-base that Apple hopes to woe. Apple claims that Safari is twice as fast IE7 and up to 1.6 times faster than Firefox 2 at rendering web pages, in addition to having a superior user interface. However, on the Safari download page, out of the twelve reasons Apple gives for loving Safari, security comes up in the last spot -- we here at Neoseeker hope that this twelfth place position is not indicative of its priority in Safari's further development.  

  Related Stories

back to news    comments or corrections
- This news story is archived and is closed to comments now -

Comments:

June 12th, 2007 3:50PM(PT)
Menkoy
I hope they fix this, as I'd love a faster web browser.
June 12th, 2007 4:13PM(PT)
jmicahg
Steve Jobs is screaming his head off at his programmers as we speak. They're not going to sleep until everything is a-okay, Steve will make certian of that.
June 12th, 2007 5:28PM(PT)
kspiess
I sort of think that these variety of securities flaws can be somewhat anticipated with the first Safari PC release. Guess we'll see what Apple does; it's in their best interest to patch stuff up asap.

Thanks for the comments on my first news story for Neoseeker guys!
June 12th, 2007 6:41PM(PT)
twizttid13
I tested Safari and actually Firefox is faster for me. Although it could be because I tweaked Firefox. But at least I have both features and a fast web browser, I also find it simpler to use then Safari. I don't think Safari has many features, but if it does, someone correct me.
June 13th, 2007 8:54AM(PT)
leochan
I can't stand Safari's built-in text smoothing personally. It makes everything look so durned fuzzy.
June 13th, 2007 9:53AM(PT)
kspiess
Ya, I wasn't terribly impressed by the screenshots I have seen. For now, I think I'll just stick with Firefox.

- This news story is archived and is closed to new comments now -

  RSS Feeds

Latest Comments
Most Comments

Latest Net Reviews:
Latest Inhouse:


Compare Prices

Motherboards
 Abit
 ASUS
 Gigabyte
 Intel
 iWill
 Shuttle
 Soyo
 Super Micro
 Tyan
 More...

Processors
 AMD
 Intel
 More...

Memory
 SDRAM
 RDRAM
 DDRAM
 More...

Video Cards
 ATI
 Visiontek
 PNY
 3Dfx
 More...

search for lowest prices
(0.0200/mc/nova)