Safari 5.1, the browser bundled with Lion, also makes its way to Snow Leopard
Apple today updated Safari to version 5.1, patching 58 security vulnerabilities and adding several new features, including sandboxing on Mac OS X 10.7.
Safari 5.1 is the browser bundled with Lion, the operating system Apple released earlier today, but it will also run on Mac OS X 10.6, aka Snow Leopard. A separate Safari update to version 5.0.6 was also issued today for users running Mac OS X 10.5, or Leopard.
The update patched a total of 58 flaws in Safari, 14 of them specific to the Windows edition, one that affected only the Mac version, and 44 that impact both platforms. Forty-seven of the 58 were accompanied by Apple's "arbitrary code execution" phrasing, indicating that the company considered them critical.
Unlike rival Microsoft, Apple does not tag vulnerabilities with threat-level labels.
Safari was last patched in April when Apple fixed two flaws. The month before that, however, Apple addressed 62 vulnerabilities in a massive security update.
The bulk of the bugs patched today -- 43 of the 58 -- were in WebKit, the open-source browser engine that powers Safari and also Google's Chrome.
Most of those were memory flaws.
"Multiple memory corruption issues existed in WebKit," said Apple in the security advisory that accompanied the Safari 5.1 update. "Visiting a maliciously-crafted website may lead to an unexpected application termination or arbitrary code execution."
Apple's description means that the vulnerabilities could be exploited via "drive-by" attacks that only require cyber criminals to trick victims into visiting a malware-serving URL.
Along with the patches, Apple also added new features to Safari 5.1, including Reading List, a feature inspired by the third-party program Instapaper, that eliminates Web ads on content marked for later viewing.
Safari 5.1 supports several Lion-only features as well, ranging from the operating system's multi-touch support and full-screen view to automatic resume and "sandboxing," an anti-exploit technology that isolates the browser from the rest of the machine.
Reading List
Safari 5.1 runs on Snow Leopard, but only some features -- like Reading List -- are available. The new browser runs best on Lion.
Like Chrome has done since its 2008 debut, Safari 5.1 insulates the operating system and other applications from any code executed in the browser, including attack code.
"If a website contains malicious code intended to capture personal data or take control of your computer, sandboxing automatically blocks it to keep your computer and your information safe," Apple claimed on its Safari 5.1 website today.
Chrome's sandbox has kept it more secure than other browsers from attacks, including those launched by top-notch researchers at the annual Pwn2Own challenge, where Google's browser has never been hacked.
Safari can be downloaded for Leopard or Snow Leopard on a Mac, and for Windows XP, Vista and Windows 7 on a PC, from Apple's website. Mac OS X users will be notified of the new version automatically, while Windows users already running Safari will be alerted by the Apple Software Update tool.
July 20, 2011
July 19, 2011
Microsoft beefs up Outlook-to-Hotmail security
Adds HTTPS support to Outlook Hotmail Connector tool for Windows
Computerworld - Microsoft on Thursday boosted the security of a tool that lets Outlook users send and receive messages through the company's Web-based Hotmail service.
The new Outlook Hotmail Connector supports HTTPS, a protocol that encrypts all traffic between the email client and the Windows Live Hotmail service.
Microsoft added an all-HTTPS option to Hotmail in November 2010, in part as a reaction to Firesheep, a Firefox add-on released the month earlier that let anyone scan an unsecured Wi-Fi network and hijack others' access to Facebook, Twitter and a host of other services.
This week's update to Outlook Hotmail Connector is a follow-up to Microsoft's 2010 move.
"Using a connection with HTTPS helps you be even more confident that your account is safer from hijackers, and that your private information remains private," the Outlook team wrote on its official blog Thursday.
The new tool encrypts communication between Outlook and the Windows Live email, calendar and contacts services.
Google's Gmail beat Hotmail to the HTTPS punch by years.
Gmail users have had the option of encrypting all Gmail traffic since 2008, but in mid-January 2010, Google enabled HTTPS by default on the same day it accused Chinese hackers of breaking into its systems and trying to access the Gmail accounts of human rights activists who live in the country.
Microsoft has also updated the consumer-grade Windows Live Mail to support HTTPS. Unlike its Outlook Express predecessor, which was bundled with Windows XP, Windows Live Mail is an optional download for Vista and Windows 7.
Outlook Hotmail Connector can be downloaded in 32-bit and 64-bit versions for Outlook 2003, 2007 and 2010 on Windows. There is no similar tool for Outlook 2011, the email program included with Office for Mac 2011.
The Windows Live Essentials update -- which includes the HTTPS-enabled Windows Live Mail -- is also available on Microsoft's download website.
Computerworld - Microsoft on Thursday boosted the security of a tool that lets Outlook users send and receive messages through the company's Web-based Hotmail service.
The new Outlook Hotmail Connector supports HTTPS, a protocol that encrypts all traffic between the email client and the Windows Live Hotmail service.
Microsoft added an all-HTTPS option to Hotmail in November 2010, in part as a reaction to Firesheep, a Firefox add-on released the month earlier that let anyone scan an unsecured Wi-Fi network and hijack others' access to Facebook, Twitter and a host of other services.
This week's update to Outlook Hotmail Connector is a follow-up to Microsoft's 2010 move.
"Using a connection with HTTPS helps you be even more confident that your account is safer from hijackers, and that your private information remains private," the Outlook team wrote on its official blog Thursday.
The new tool encrypts communication between Outlook and the Windows Live email, calendar and contacts services.
Google's Gmail beat Hotmail to the HTTPS punch by years.
Gmail users have had the option of encrypting all Gmail traffic since 2008, but in mid-January 2010, Google enabled HTTPS by default on the same day it accused Chinese hackers of breaking into its systems and trying to access the Gmail accounts of human rights activists who live in the country.
Microsoft has also updated the consumer-grade Windows Live Mail to support HTTPS. Unlike its Outlook Express predecessor, which was bundled with Windows XP, Windows Live Mail is an optional download for Vista and Windows 7.
Outlook Hotmail Connector can be downloaded in 32-bit and 64-bit versions for Outlook 2003, 2007 and 2010 on Windows. There is no similar tool for Outlook 2011, the email program included with Office for Mac 2011.
The Windows Live Essentials update -- which includes the HTTPS-enabled Windows Live Mail -- is also available on Microsoft's download website.
July 18, 2011
Microsoft plans 22 patches for Windows, Office next week
Sole critical bulletin will fix flaws only in Vista and Windows 7
Computerworld - Microsoft today said it will issue four security updates next week, only one of which is pegged as critical, to patch 22 vulnerabilities in Windows and Visio 2003.
Next Tuesday's patch lineup is smaller than June's, when Microsoft shipped 16 updates that fixed 34 flaws. The company typically delivers a lighter load in odd-numbered months. In May, for instance, Microsoft shipped just two updates -- the company calls them "bulletins" -- to patch only three vulnerabilities.
Of the four updates slated, one will be rated "critical," the highest threat label in Microsoft's four-step scoring system, while the other three will be marked "important," the second-most-dire ranking.
Next week's Patch Tuesday vulnerability count will be among the largest for the year, with its 22 bested only by April's 64 and June's 34, and tied with February's collection.
But the bugs-per-bulletins ratio is the highest for the year, observed Andrew Storms, director of security operations at nCircle Security, hinting of next week's releases.
"I think we'll see one bulletin with a very high number of vulnerabilities," said Storms. "We've seen that happen several times this year, most recently last month when it patched eight bugs in Excel with one update.
In April, Microsoft patched 30 vulnerabilities in the Windows kernel device driver with a single bulletin, a record for one update.
Storms said that the multi-bug update coming next Tuesday may fix numerous "elevation of privilege" vulnerabilities or a large number of "DDL load hijacking" flaws.
The former describes a bug attackers can use to gain complete administrative control of a system that they can already access, perhaps through an exploit of a separate vulnerability. DLL load hijacking, on the other hand, is the term used for attacks that rely on tricking applications or operating systems into loading a malicious file with the same name as a legitimate DLL, or dynamic link library.
Microsoft has issued more than a dozen DLL load hijacking updates since last November. In May, the Slovenian firm Acros Security announced that more DLL load hijacking updates were necessary to plug holes in Windows 7 and Internet Explorer 9 (IE9). At the time, Microsoft said only that it was investigating the Acros report.
The sole critical update scheduled for next week affects Windows Vista and Windows 7, but does not impact the much older Windows XP or any of Microsoft's server operating systems.
Because Windows XP will be immune to the one or more vulnerabilities in that update, Storms said the bug had to be in code first used in Vista, then reused in Windows 7. He noted there are multiple candidates that fit the bill, including the security prompting component called UAC -- for "user account control" -- but said there wasn't sufficient information to take an educated guess.
Computerworld - Microsoft today said it will issue four security updates next week, only one of which is pegged as critical, to patch 22 vulnerabilities in Windows and Visio 2003.
Next Tuesday's patch lineup is smaller than June's, when Microsoft shipped 16 updates that fixed 34 flaws. The company typically delivers a lighter load in odd-numbered months. In May, for instance, Microsoft shipped just two updates -- the company calls them "bulletins" -- to patch only three vulnerabilities.
Of the four updates slated, one will be rated "critical," the highest threat label in Microsoft's four-step scoring system, while the other three will be marked "important," the second-most-dire ranking.
Next week's Patch Tuesday vulnerability count will be among the largest for the year, with its 22 bested only by April's 64 and June's 34, and tied with February's collection.
But the bugs-per-bulletins ratio is the highest for the year, observed Andrew Storms, director of security operations at nCircle Security, hinting of next week's releases.
"I think we'll see one bulletin with a very high number of vulnerabilities," said Storms. "We've seen that happen several times this year, most recently last month when it patched eight bugs in Excel with one update.
In April, Microsoft patched 30 vulnerabilities in the Windows kernel device driver with a single bulletin, a record for one update.
Storms said that the multi-bug update coming next Tuesday may fix numerous "elevation of privilege" vulnerabilities or a large number of "DDL load hijacking" flaws.
The former describes a bug attackers can use to gain complete administrative control of a system that they can already access, perhaps through an exploit of a separate vulnerability. DLL load hijacking, on the other hand, is the term used for attacks that rely on tricking applications or operating systems into loading a malicious file with the same name as a legitimate DLL, or dynamic link library.
Microsoft has issued more than a dozen DLL load hijacking updates since last November. In May, the Slovenian firm Acros Security announced that more DLL load hijacking updates were necessary to plug holes in Windows 7 and Internet Explorer 9 (IE9). At the time, Microsoft said only that it was investigating the Acros report.
The sole critical update scheduled for next week affects Windows Vista and Windows 7, but does not impact the much older Windows XP or any of Microsoft's server operating systems.
Because Windows XP will be immune to the one or more vulnerabilities in that update, Storms said the bug had to be in code first used in Vista, then reused in Windows 7. He noted there are multiple candidates that fit the bill, including the security prompting component called UAC -- for "user account control" -- but said there wasn't sufficient information to take an educated guess.
Subscribe to:
Posts (Atom)