Apple Releases iPhone Software Version 1.0.1

Apple has released iPhone Software Version 1.0.1 that includes some bug fixes.
http://docs.info.apple.com/article.html?artnum=306173

iPhone v1.0.1 Update

  • Safari
    CVE-ID: CVE-2007-2400
    Available for: iPhone v1.0
    Impact: Visiting a malicious website may allow cross-site scripting
    Description: Safari’s security model prevents JavaScript in remote web pages from modifying pages outside of their domain. A race condition in page updating combined with HTTP redirection may allow JavaScript from one page to modify a redirected page. This could allow cookies and pages to be read or arbitrarily modified. This update addresses the issue by correcting access control to window properties. Credit to Lawrence Lai, Stan Switzer, and Ed Rowe of Adobe Systems, Inc. for reporting this issue.
  • Safari
    CVE-ID: CVE-2007-3944
    Available for: iPhone v1.0
    Impact: Viewing a maliciously crafted web page may lead to arbitrary code execution
    Description: Heap buffer overflows exist in the Perl Compatible Regular Expressions (PCRE) library used by the JavaScript engine in Safari. By enticing a user to visit a maliciously crafted web page, an attacker may trigger the issue, which may lead to arbitrary code execution. This update addresses the issue by performing additional validation of JavaScript regular expressions. Credit to Charlie Miller and Jake Honoroff of Independent Security Evaluators for reporting these issues
  • WebCore
    CVE-ID: CVE-2007-2401
    Available for: iPhone v1.0
    Impact: Visiting a malicious website may allow cross-site requests
    Description: An HTTP injection issue exists in XMLHttpRequest when serializing headers into an HTTP request. By enticing a user to visit a maliciously crafted web page, an attacker could trigger a cross-site scripting issue. This update addresses the issue by performing additional validation of header parameters. Credit to Richard Moore of Westpoint Ltd. for reporting this issue.
  • WebKit
    CVE-ID: CVE-2007-3742
    Available for: iPhone v1.0
    Impact: Look-alike characters in a URL could be used to masquerade a website
    Description: The International Domain Name (IDN) support and Unicode fonts embedded in Safari could be used to create a URL which contains look-alike characters. These could be used in a malicious web site to direct the user to a spoofed site that visually appears to be a legitimate domain. This update addresses the issue by through an improved domain name validity check.
  • WebKit
    CVE-ID: CVE-2007-2399
    Available for: iPhone v1.0
    Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution
    Description: An invalid type conversion when rendering frame sets could lead to memory corruption. Visiting a maliciously crafted web page may lead to an unexpected application termination or arbitrary code execution. Credit to Rhys Kidd of Westnet for reporting this issue.

Other Bug Fixes found:

  • VPN Client – No longer asking for “numerical-only” passwords when turned on

The update can be obtained through iTunes (7.3.x or higher required)
http://docs.info.apple.com/article.html?artnum=305744
http://www.apple.com/support/iphone/

iPhone Sovtware Version 1.0.1

Apple: Security Updates, Airport Extreme, Pro Application Supports, and Bonjour

Apple has been busy releasing updates to its softwares.

07.31.2007
Security Update 2007-007 is recommended for all users.
Security Update 2007-007 (10.3.9)48.7MB
Security Update 2007-007 (10.3.9 Server)63.3MB
Security Update 2007-007 (10.4.10 PPC)14.2MB
Security Update 2007-007 (10.4.10 Server PPC)23.8MB
Security Update 2007-007 (10.4.10 Universal)25.7MB
Security Update 2007-007 (10.4.10 Server Universal)35.3MB

AirPort Extreme Update 2007-004745KB
This update is recommended for all Intel-based MacBook, MacBook Pro, and Mac mini computers and improves the reliability of AirPort connections.

07.30.2007
Pro Application Support 4.0.17.6MB
This update improves general user interface reliability for Apple’s professional applications.

07.26.2007
Bonjour for Windows 1.0.42.1MB
This update is recommended for all Bonjour users to improve usability and compatibility.

Apple Releases Security Update 2007-006 for Mac OS X 10.3.9 and 10.4.9

Apple releases “Security Update 2007-006” coinciding with the release of Safari 3.0.2 Beta update. The update is available for Mac OS X 10.3.9 and 10.4.9 (or higher).

This Security Update is included in Safari 3.0.2 Beta.

Security Update 2007-006 is recommended for all users and improves the security of the WebKit component.

06/22/2007
Security Update 2007-006 (10.3.9)2.2MB
Security Update 2007-006 (Universal)4.5MB
Security Update 2007-006 (PPC)2.7MB

The “Security Update 2007-006” is available through Apple Software Update and Apple Support Download Page.

Mac OS X 10.4.10 is Released

Apple released Mac OS X 10.4.10 for PPC and Intel Macs.

Mac OS X 10.4.10 Client for PowerPC Mac – Build 8R218
Mac OS X 10.4.10 Client for Intel Mac – Build 8R2218

for some reasons, Apple Remote Desktop 3.1 lists Macs with 10.4.10 as 10.4.9 but with the correct build numbers.

Apple Remote Desktop - Mac OS X 10.4.10 with Build Numbers

06/20/2007
Mac OS X 10.4.10 Client and Server Update

What’s New in this Version
The 10.4.10 Update is recommended for PowerPC and Intel-based Mac computers currently running Mac OS X Tiger. This update includes general operating system fixes, as well as specific fixes or compatibility updates for the following applications and technologies:

  • RAW camera support
  • Mounting and unmounting external USB devices
  • Support for 3rd party software applications
  • Security updates

Mac OS X 10.4.10 Update (PPC)25MB
Mac OS X 10.4.10 Combo Update (PPC)165MB
Mac OS X 10.4.10 Update (Intel)72MB
Mac OS X 10.4.10 Combo Update (Intel)293MB
Mac OS X Server 10.4.10 Update (PPC)58MB
Mac OS X Server 10.4.10 Combo Update (PPC)218MB
Mac OS X Server 10.4.10 Combo Update (Universal)391MB

Apple released Mac OS X 10.4.10 for PPC and Intel Macs.

Mac OS X 10.4.10 Client for PowerPC Mac – Build 8R218
Mac OS X 10.4.10 Client for Intel Mac – Build 8R2218

for some reasons, Apple Remote Desktop 3.1 lists Macs with 10.4.10 as 10.4.9 but with the correct build numbers.

Apple Remote Desktop - Mac OS X 10.4.10 with Build Numbers

06/20/2007
Mac OS X 10.4.10 Client and Server Update

What’s New in this Version
The 10.4.10 Update is recommended for PowerPC and Intel-based Mac computers currently running Mac OS X Tiger. This update includes general operating system fixes, as well as specific fixes or compatibility updates for the following applications and technologies:

  • RAW camera support
  • Mounting and unmounting external USB devices
  • Support for 3rd party software applications
  • Security updates

Mac OS X 10.4.10 Update (PPC)25MB
Mac OS X 10.4.10 Combo Update (PPC)165MB
Mac OS X 10.4.10 Update (Intel)72MB
Mac OS X 10.4.10 Combo Update (Intel)293MB
Mac OS X Server 10.4.10 Update (PPC)58MB
Mac OS X Server 10.4.10 Combo Update (PPC)218MB
Mac OS X Server 10.4.10 Combo Update (Universal)391MB