{"id":666,"date":"2008-04-16T14:05:41","date_gmt":"2008-04-16T22:05:41","guid":{"rendered":"http:\/\/37prime.wordpress.com\/?p=666"},"modified":"2008-04-16T14:05:41","modified_gmt":"2008-04-16T22:05:41","slug":"safari-311-is-available","status":"publish","type":"post","link":"https:\/\/37prime.com\/news\/2008\/04\/16\/safari-311-is-available\/","title":{"rendered":"Safari 3.1.1 is Available"},"content":{"rendered":"<p><img decoding=\"async\" src=\"http:\/\/37prime.com\/news\/wp-content\/uploads\/2008\/03\/safari_icon.png\" alt=\"Safari Icon\" \/><\/p>\n<p>Apple releases <a href=\"http:\/\/www.apple.com\/support\/downloads\/safari311.html\" target=\"_blank\">Safari 3.1.1<\/a> to address stability, compatibility and Security.<\/p>\n<p>Safari 3.1.1 is available for Mac OS X Tiger, Leopard, and Windows XP\/Vista.<\/p>\n<p><a href=\"http:\/\/support.apple.com\/kb\/HT1467\" target=\"_blank\">About the security content of Safari 3.1.1<\/a><\/p>\n<blockquote><p><em>Safari 3.1.1<br \/>\n<\/em><\/p>\n<ul>\n<li><em>Safari<br \/>\nCVE-ID: CVE-2007-2398<br \/>\nAvailable for: Windows XP or Vista<br \/>\nImpact: A maliciously crafted website may control the contents of the address bar<\/em><em><br \/>\nDescription: A timing issue in Safari 3.1 allows a web page to change the contents of the address bar without loading the contents of the corresponding page. This could be used to spoof the contents of a legitimate site, allowing user credentials or other information to be gathered. This issue was addressed in Safari Beta 3.0.2, but reintroduced in Safari 3.1. This update addresses the issue by restoring the address bar contents if a request for a new web page is terminated. This issue does not affect Mac OS X systems.<\/em><\/li>\n<\/ul>\n<ul>\n<li><em>Safari<br \/>\nCVE-ID: CVE-2008-1024<br \/>\nAvailable for: Windows XP or Vista<br \/>\nImpact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution<\/em><em><br \/>\nDescription: A memory corruption issue exists in Safari&#8217;s file downloading. By enticing a user to download a file with a maliciously crafted name, an attacker may cause an unexpected application termination or arbitrary code execution. This update addresses the issue through improved handling of file downloads. This issue does not affect Mac OS X systems.<\/em><\/li>\n<\/ul>\n<ul>\n<li><em>WebKit<br \/>\nCVE-ID: CVE-2008-1025<br \/>\nAvailable for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.2, Mac OS X Server v10.5.2, Windows XP or Vista<br \/>\nImpact: Visiting a malicious website may result in cross-site scripting<\/em><em><br \/>\nDescription: An issue exists in WebKi&#8217;s handling of URLs containing a colon character in the host name. Opening a maliciously crafted URL may lead to a cross-site scripting attack. This update addresses the issue through improved handling of URLs. Credit to Robert Swiecki of Google Information Security Team and David Bloom for reporting this issue.<\/em><\/li>\n<\/ul>\n<ul>\n<li><em>WebKit<br \/>\nCVE-ID: CVE-2008-1026<br \/>\nAvailable for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.2, Mac OS X Server v10.5.2, Windows XP or Vista<br \/>\nImpact: Viewing a maliciously crafted web page may lead to an unexpected application termination or arbitrary code execution<\/em><em><br \/>\nDescription: A heap buffer overflow exists in WebKit&#8217;s handling of JavaScript regular expressions. The issue may be triggered via JavaScript when processing regular expressions with large, nested repetition counts. This may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation of JavaScript regular expressions. Credit to Charlie Miller for reporting these issues.<\/em><\/li>\n<\/ul>\n<\/blockquote>\n<p>Safari 3.1.1 can be obtained through <a href=\"http:\/\/www.apple.com\/safari\/\" target=\"_blank\">Safari Download Page<\/a> or Apple Software Updates.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Apple releases Safari 3.1.1 to address stability, compatibility and Security. Safari 3.1.1 is available for Mac OS X Tiger, Leopard, and Windows XP\/Vista. About the security content of Safari 3.1.1 Safari 3.1.1 Safari CVE-ID: CVE-2007-2398 Available for: Windows XP or Vista Impact: A maliciously crafted website may control the contents of the address bar Description: &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/37prime.com\/news\/2008\/04\/16\/safari-311-is-available\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Safari 3.1.1 is Available&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[946,4],"tags":[403,404,1851,1931,2009,2511,2586,2648,936,3131,3176,3179,3216],"class_list":["post-666","post","type-post","status-publish","format-standard","hentry","category-announcements","category-news","tag-applications","tag-apps","tag-leopard","tag-mac-os-x","tag-media","tag-resources","tag-safari","tag-security","tag-tech","tag-vista","tag-web-browsers","tag-webkit","tag-windows"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/pcNtU-aK","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/posts\/666","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/comments?post=666"}],"version-history":[{"count":0,"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/posts\/666\/revisions"}],"wp:attachment":[{"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/media?parent=666"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/categories?post=666"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/tags?post=666"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}