Apple issues security update for Safari
Published: 12 Nov 2009 10:00 GMT
Apple released a security update for its Safari web browser on Wednesday.
Available for Windows and Mac, Safari 4.0.4 addresses a wide range of problem points. On both Windows and Mac, parsing maliciously written XML content could have led to a browser crash, using shortcut menu options within a maliciously created website could have led to the disclosure of local information, and visiting a maliciously built website could have resulted in unexpected actions on other opened websites.
For Windows only, viewing a maliciously made image with an embedded colour profile that could lead to a browser crash or running arbitrary code is no longer a threat, nor is accessing a maliciously crafted FTP server, which could have led to an unexpected crash, information disclosure, or arbitrary code execution. For Mac only, an exploit that could have allowed email to remotely load audio and video content when loading a remote image has been disabled.
For more on this story, see Apple updates Safari for security on CNET News.











