<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress.com" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>apple-safari &amp;laquo; WordPress.com Tag Feed</title>
	<link>http://wordpress.com/tag/apple-safari/</link>
	<description>Feed of posts on WordPress.com tagged "apple-safari"</description>
	<pubDate>Sun, 06 Jul 2008 16:24:00 +0000</pubDate>

	<generator>http://wordpress.com/tags/</generator>
	<language>en</language>

<item>
<title><![CDATA[June Security Updates for OS X and Safari for Mac]]></title>
<link>http://bardissi.wordpress.com/?p=423</link>
<pubDate>Tue, 01 Jul 2008 18:58:55 +0000</pubDate>
<dc:creator>bardissi</dc:creator>
<guid>http://bardissi.wordpress.com/?p=423</guid>
<description><![CDATA[Severity: High
1 July, 2008
Summary:
§  These vulnerabilities affect: OS X 10.4.x (Tiger) and OS X]]></description>
<content:encoded><![CDATA[<h3 style="margin:11.25pt 0 1.5pt;"><span style="font-size:x-small;"><span style="font-family:Verdana;"><span style="color:black;">Severity: </span><span style="color:red;">High</span><span style="color:black;"></span></span></span></h3>
<p class="date" style="margin:0 0 7.5pt;"><strong><span style="font-size:x-small;color:#a8a8a8;font-family:Tahoma;">1 July, 2008</span></strong></p>
<h3 style="margin:11.25pt 0 1.5pt;"><span style="color:black;"><span style="font-size:x-small;"><span style="font-family:Verdana;">Summary:</span></span></span></h3>
<p class="MsoNormal" style="text-indent:-0.25in;margin:3.75pt 0 0 32.25pt;"><span style="font-size:10pt;color:black;font-family:Wingdings;"><span>§<span style="font:7pt &#34;">  </span></span></span><strong><span style="font-size:9pt;color:black;font-family:&#34;">These vulnerabilities affect:</span></strong><span style="font-size:9pt;color:black;font-family:&#34;"> OS X 10.4.x (Tiger) and OS X 10.5.x (Leopard), both client and server versions; as well as Safari 3.x for OS X 10.4.x </span></p>
<p class="MsoNormal" style="text-indent:-0.25in;margin:3.75pt 0 0 32.25pt;"><span style="font-size:10pt;color:black;font-family:Wingdings;"><span>§<span style="font:7pt &#34;">  </span></span></span><strong><span style="font-size:9pt;color:black;font-family:&#34;">How an attacker exploits them:</span></strong><span style="font-size:9pt;color:black;font-family:&#34;"> Multiple vectors of attack, including enticing one of your users into visiting a malicious web site </span></p>
<p class="MsoNormal" style="text-indent:-0.25in;margin:3.75pt 0 0 32.25pt;"><span style="font-size:10pt;color:black;font-family:Wingdings;"><span>§<span style="font:7pt &#34;">  </span></span></span><strong><span style="font-size:9pt;color:black;font-family:&#34;">Impact:</span></strong><span style="font-size:9pt;color:black;font-family:&#34;"> Various results; in the worst case, attacker executes code on your user's computer, potentially gaining control of your user's computer </span></p>
<p class="MsoNormal" style="text-indent:-0.25in;margin:3.75pt 0 0 32.25pt;"><span style="font-size:10pt;color:black;font-family:Wingdings;"><span>§<span style="font:7pt &#34;">  </span></span></span><strong><span style="font-size:9pt;color:black;font-family:&#34;">What to do:</span></strong><span style="font-size:9pt;color:black;font-family:&#34;"> OS X administrators should download, test and install Security Update 2008-004, Mac OS X 10.5.4, and Safari 3.1.2 </span></p>
<h3 style="margin:11.25pt 0 1.5pt;"><span style="color:black;"><span style="font-size:x-small;"><span style="font-family:Verdana;">Exposure:</span></span></span></h3>
<p><span style="font-size:x-small;font-family:Verdana;">Late yesterday, Apple released two security updates to fix vulnerabilities in both OS X and Safari for Mac. The </span><a href="http://support.apple.com/kb/HT2163"><span style="font-size:x-small;color:#ee0000;font-family:Verdana;">OS X security update</span></a><span style="font-size:x-small;font-family:Verdana;"> fixes around 25 (number based on </span><a href="http://cve.mitre.org/"><span style="font-size:x-small;color:#ee0000;font-family:Verdana;">CVE-ID</span></a><span style="font-size:x-small;font-family:Verdana;">s) security issues in software packages that ship as part of OS X, including Ruby, Tomcat, and Webkit. Some of these vulnerabilities allow attackers to execute code on your OS X machines, so we rate this update Critical. Apply it as soon as you can. Three of the fixed vulnerabilities include:</span></p>
<p class="MsoNormal" style="text-indent:-0.25in;margin:3.75pt 0 0 32.25pt;"><span style="font-size:10pt;color:black;font-family:Wingdings;"><span>§<span style="font:7pt &#34;">  </span></span></span><strong><span style="font-size:9pt;color:black;font-family:&#34;">WebKit code execution vulnerability.</span></strong><span style="font-size:9pt;color:black;font-family:&#34;"> WebKit is an OS X framework used to help display the various types of content found in web pages. According to Apple, Webkit suffers from a memory corruption vulnerability involving the way it processes JavaScript arrays. By luring one of your users to a maliciously crafted web page, an attacker could exploit this flaw to execute code on your user's computer, with that user's privileges. </span></p>
<p class="MsoNormal" style="text-indent:-0.25in;margin:3.75pt 0 0 32.25pt;"><span style="font-size:10pt;color:black;font-family:Wingdings;"><span>§<span style="font:7pt &#34;">  </span></span></span><strong><span style="font-size:9pt;color:black;font-family:&#34;">SMB File Server buffer overflow vulnerability.</span></strong><span style="font-size:9pt;color:black;font-family:&#34;"> The SMB File Server allows OS X to share files with Windows computers. SMB File Server suffers from a heap <a href="http://www.webopedia.com/TERM/b/buffer_overflow.html"><span style="font-size:12pt;"><span style="color:#ee0000;">buffer overflow vulnerability</span></span></a> involving the way it handles SMB packets. By sending specially crafted packets to an SMB File Server, or by enticing one of your users to connect to a malicious SMB File Server, an attacker can exploit this flaw to execute code on that user's computer. </span></p>
<p class="MsoNormal" style="text-indent:-0.25in;margin:3.75pt 0 0 32.25pt;"><span style="font-size:10pt;color:black;font-family:Wingdings;"><span>§<span style="font:7pt &#34;">  </span></span></span><strong><span style="font-size:9pt;color:black;font-family:&#34;">Launch Services code execution vulnerability. </span></strong><span style="font-size:9pt;color:black;font-family:&#34;">Launch Services is an OS X <a href="http://www.watchguard.com/glossary/a.asp#API"><span style="font-size:12pt;"><span style="color:#ee0000;">application programming interface (API)</span></span></a> that allows a running application to open other applications, or their documents. Launch Services suffers from something called a <span class="style31"><a href="http://en.wikipedia.org/wiki/Race_condition"><span style="font-size:12pt;"><span style="color:#ee0000;">race condition vulnerability</span></span></a></span>, having to do with its validation of <span class="style31"><a href="http://en.wikipedia.org/wiki/Symbolic_link"><span style="font-size:12pt;"><span style="color:#ee0000;">symbolic links</span></span></a></span>. By luring one of your users to a specially created web site, an attacker can exploit this flaw to execute code on that user's computer, with that user's privileges. However, this attack can only succeed if your users has enabled the "<em>Open 'safe' files</em>" preference in Safari. </span></p>
<p><span style="font-size:x-small;font-family:Verdana;">Apple's alert includes many more flaws, including other code execution flaws in addition to those described above. The remaining vulnerabilities also include </span><a href="http://www.watchguard.com/glossary/d.asp#DoS"><span style="font-size:x-small;color:#ee0000;font-family:Verdana;">Denial of Service (DoS)</span></a><span style="font-size:x-small;font-family:Verdana;"> flaws, </span><a href="http://www.watchguard.com/glossary/e.asp#elevation_of_privilege"><span style="font-size:x-small;color:#ee0000;font-family:Verdana;">elevation of privilege</span></a><span style="font-size:x-small;font-family:Verdana;"> flaws, and spoofing vulnerabilities, plus others. Components patched by this security update include:</span></p>
<table class="MsoNormalTable" style="width:225pt;margin:auto auto auto 0.5in;" border="1" cellpadding="0" width="300">
<tbody>
<tr>
<td style="width:105pt;background-color:transparent;border:#f0f0f0;padding:0.75pt;" width="140"><span style="font-size:x-small;">Alias Manager </span></td>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><span style="font-size:x-small;">CoreTypes</span></td>
</tr>
<tr>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><span style="font-size:x-small;">c++filt</span></td>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><span style="font-size:x-small;">Dock</span></td>
</tr>
<tr>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><span style="font-size:x-small;">Launch Services </span></td>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><span style="font-size:x-small;">Net-SNMP</span></td>
</tr>
<tr>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><span style="font-size:x-small;">Ruby</span></td>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><span style="font-size:x-small;">SMB File Server </span></td>
</tr>
<tr>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><span style="font-size:x-small;">System Configuration </span></td>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><span style="font-size:x-small;">Tomcat</span></td>
</tr>
<tr>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><span style="font-size:x-small;">VPN</span></td>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><span style="font-size:x-small;">Webkit</span></td>
</tr>
</tbody>
</table>
<p><span style="font-size:x-small;font-family:Verdana;">Please refer to </span><a href="http://support.apple.com/kb/HT2163"><span style="font-size:x-small;color:#ee0000;font-family:Verdana;">Apple's OS X alert</span></a><span style="font-size:x-small;font-family:Verdana;"> for more details.</span></p>
<p><span style="font-size:x-small;font-family:Verdana;">Apple also released a small </span><a href="http://support.apple.com/kb/HT2165"><span style="font-size:x-small;color:#ee0000;font-family:Verdana;">security update</span></a><span style="font-size:x-small;font-family:Verdana;"> for Safari 3.x. This update fixes one serious vulnerability that only affects Tiger (OS X 10.4.x) users. This flaw is identical to the Webkit vulnerability described above. For some reason, though, Tiger users must also apply this Safari update in order to completely patch the vulnerability.</span></p>
<h3 style="margin:11.25pt 0 1.5pt;"><span style="color:black;"><span style="font-size:x-small;"><span style="font-family:Verdana;">Solution Path:</span></span></span></h3>
<p><span style="font-size:x-small;font-family:Verdana;">Apple has released OS X Security Update 2008-004, OS X 10.5.4, and Safari 3.1.2 to fix all these security issues. OS X administrators should download, test, and deploy the corresponding update as soon as they can.</span></p>
<p class="MsoNormal" style="text-indent:-0.25in;margin:3.75pt 0 0 32.25pt;"><span style="font-size:10pt;color:black;font-family:Wingdings;"><span>§<span style="font:7pt &#34;">  </span></span></span><span style="font-size:9pt;color:black;font-family:&#34;"><a href="http://www.apple.com/support/downloads/securityupdate2008004ppc.html"><span style="font-size:12pt;"><span style="color:#ee0000;">Security Update 2008-004 (PPC)</span></span></a> </span></p>
<p class="MsoNormal" style="text-indent:-0.25in;margin:3.75pt 0 0 32.25pt;"><span style="font-size:10pt;color:black;font-family:Wingdings;"><span>§<span style="font:7pt &#34;">  </span></span></span><span style="font-size:9pt;color:black;font-family:&#34;"><a href="http://www.apple.com/support/downloads/securityupdate2008004intel.html"><span style="font-size:12pt;"><span style="color:#ee0000;">Security Update 2008-004 (Intel)</span></span></a> </span></p>
<p class="MsoNormal" style="text-indent:-0.25in;margin:3.75pt 0 0 32.25pt;"><span style="font-size:10pt;color:black;font-family:Wingdings;"><span>§<span style="font:7pt &#34;">  </span></span></span><span style="font-size:9pt;color:black;font-family:&#34;"><a href="http://www.apple.com/support/downloads/securityupdate2008004serverppc.html"><span style="font-size:12pt;"><span style="color:#ee0000;">Security Update 2008-004 Server (PPC)</span></span></a> </span></p>
<p class="MsoNormal" style="text-indent:-0.25in;margin:3.75pt 0 0 32.25pt;"><span style="font-size:10pt;color:black;font-family:Wingdings;"><span>§<span style="font:7pt &#34;">  </span></span></span><span style="font-size:9pt;color:black;font-family:&#34;"><a href="http://www.apple.com/support/downloads/securityupdate2008004serverintel.html"><span style="font-size:12pt;"><span style="color:#ee0000;">Security Update 2008-004 Server (Intel)</span></span></a> </span></p>
<p class="MsoNormal" style="text-indent:-0.25in;margin:3.75pt 0 0 32.25pt;"><span style="font-size:10pt;color:black;font-family:Wingdings;"><span>§<span style="font:7pt &#34;">  </span></span></span><span style="font-size:9pt;color:black;font-family:&#34;"><a href="http://www.apple.com/support/downloads/macosx1054update.html"><span style="font-size:12pt;"><span style="color:#ee0000;">Security Update OS X 10.5.4</span></span></a> </span></p>
<p class="MsoNormal" style="text-indent:-0.25in;margin:3.75pt 0 0 32.25pt;"><span style="font-size:10pt;color:black;font-family:Wingdings;"><span>§<span style="font:7pt &#34;">  </span></span></span><span style="font-size:9pt;color:black;font-family:&#34;"><a href="http://www.apple.com/support/downloads/macosx1054comboupdate.html"><span style="font-size:12pt;"><span style="color:#ee0000;">Security Update OS X 10.5.4 Combo Update</span></span></a> </span></p>
<p class="MsoNormal" style="text-indent:-0.25in;margin:3.75pt 0 0 32.25pt;"><span style="font-size:10pt;color:black;font-family:Wingdings;"><span>§<span style="font:7pt &#34;">  </span></span></span><span style="font-size:9pt;color:black;font-family:&#34;"><a href="http://www.apple.com/support/downloads/macosxserver1054.html"><span style="font-size:12pt;"><span style="color:#ee0000;">Security Update OS X Server 10.5.4</span></span></a> </span></p>
<p class="MsoNormal" style="text-indent:-0.25in;margin:3.75pt 0 0 32.25pt;"><span style="font-size:10pt;color:black;font-family:Wingdings;"><span>§<span style="font:7pt &#34;">  </span></span></span><span style="font-size:9pt;color:black;font-family:&#34;"><a href="http://www.apple.com/support/downloads/macosxservercombo1054.html"><span style="font-size:12pt;"><span style="color:#ee0000;">Security Update OS X Server 10.5.4 Combo Update</span></span></a> </span></p>
<p><span style="font-size:x-small;font-family:Verdana;">Note: If you have trouble figuring out which of these patches corresponds to your version of OS X and Safari, we recommend that you let OS X's Software Update utility pick the correct updates for you automatically.</span></p>
<h3 style="margin:11.25pt 0 1.5pt;"><span style="color:black;"><span style="font-size:x-small;"><span style="font-family:Verdana;">For All Users:</span></span></span></h3>
<p><span style="font-size:x-small;font-family:Verdana;">These flaws enable many diverse exploitation methods. Some of the exploits are local, meaning that your perimeter firewall never encounters the attack (unless you use firewalls internally between departments). Installing these updates, therefore, is the most secure course of action.</span></p>
<h3 style="margin:11.25pt 0 1.5pt;"><span style="color:black;"><span style="font-size:x-small;"><span style="font-family:Verdana;">Status:</span></span></span></h3>
<p><span style="font-size:x-small;font-family:Verdana;">Apple has released updates to fix these issues.</span></p>
<h3 style="margin:11.25pt 0 1.5pt;"><span style="color:black;"><span style="font-size:x-small;"><span style="font-family:Verdana;">References:</span></span></span></h3>
<p class="MsoNormal" style="text-indent:-0.25in;margin:3.75pt 0 0 32.25pt;"><span style="font-size:10pt;color:black;font-family:Wingdings;"><span>§<span style="font:7pt &#34;">  </span></span></span><span style="font-size:9pt;color:black;font-family:&#34;"><a href="http://support.apple.com/kb/HT2163"><span style="font-size:12pt;"><span style="color:#ee0000;">Apple's June OS X Advisory</span></span></a> </span></p>
<p class="MsoNormal" style="text-indent:-0.25in;margin:3.75pt 0 0 32.25pt;"><span style="font-size:10pt;color:black;font-family:Wingdings;"><span>§<span style="font:7pt &#34;">  </span></span></span><span style="font-size:9pt;color:black;font-family:&#34;"><a href="http://support.apple.com/kb/HT2165"><span style="font-size:12pt;"><span style="color:#ee0000;">Apple's June Safari Advisory</span></span></a> </span></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple iPhone 3G Announced]]></title>
<link>http://shubhamoy.wordpress.com/?p=55</link>
<pubDate>Fri, 20 Jun 2008 18:08:00 +0000</pubDate>
<dc:creator>Shubhamoy</dc:creator>
<guid>http://shubhamoy.wordpress.com/?p=55</guid>
<description><![CDATA[
Steve Jobs has just announced the new iPhone 3G at WWDC 2008. Apple’s new phone features fast 3G ]]></description>
<content:encoded><![CDATA[<p><img src="http://www.toxel.com/wp-content/uploads/2008/06/iphone3g1.jpg" alt="iPhone 3G" width="450" height="239" /></p>
<p>Steve Jobs has just announced the new <a href="http://www.apple.com/iphone/" target="_blank">iPhone 3G</a> at WWDC 2008. Apple’s new phone features fast 3G wireless technology, GPS mapping, support for enterprise features like Microsoft Exchange, and the new App Store.</p>
<blockquote><p>Apple claims its 3G speeds trounce the competition, with pageloads 36% faster than the N95 and Treo 750 — and of course it completely trounces the old EDGE data. Battery life isn’t getting put out to pasture though, with 300 hours of standby, 8-10 hours of 2G talk, 5 hours of 3G talk, 7 hours of video and 24 hours of audio.</p></blockquote>
<p>iPhone 3G will be released on July 11th in Australia, Austria, Belgium, Canada, Denmark, Finland, France, Germany, Hong Kong, Ireland, Italy, Japan, Mexico, Netherlands, New Zealand, Norway, Portugal, Spain, Sweden, Switzerland, UK and the US.</p>
<p>The price is $199 for 8G and $299 for the 16GB model.</p>
<p><img src="http://www.toxel.com/wp-content/uploads/2008/06/iphone3g2.jpg" alt="iPhone 3G" width="450" height="300" /></p>
<p>Read the full article <strong><a title="SachinKRaj's Blog" href="http://sachinkraj.wordpress.com/2008/06/20/apple-iphone-3g-announced/" target="_blank">here</a></strong>.</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox 3 - Coming on June 17]]></title>
<link>http://shubhamoy.wordpress.com/?p=40</link>
<pubDate>Wed, 11 Jun 2008 06:12:53 +0000</pubDate>
<dc:creator>Shubhamoy</dc:creator>
<guid>http://shubhamoy.wordpress.com/?p=40</guid>
<description><![CDATA[Hello Friends,
You will be amazed to know that our most lovable browser Mozilla Firefox&#8217;s Vers]]></description>
<content:encoded><![CDATA[<p>Hello Friends,</p>
<p>You will be amazed to know that our most lovable browser <strong>Mozilla Firefox's</strong> <strong>Version 3</strong>(or <strong>Gran Paradiso</strong>, its development name) is coming in few days(as told by Mozilla Engineers). So just hold your breath as the new <strong>Firefox</strong> comes. Its features are really astonishing. Let me tell you some of its features:</p>
<ul>
<li><strong><span style="color:#666699;">One-Click Bookmarking</span></strong></li>
<li><strong><span style="color:#666699;">Phishing and Malware Protection</span></strong></li>
<li><strong><span style="color:#666699;">Site ID info</span></strong></li>
<li><strong><span style="color:#666699;">Built-in spell checking</span></strong></li>
<li><strong><span style="color:#666699;">Session Restore and Full Zoom</span></strong></li>
<li><strong><span style="color:#666699;">And most shocking one, It has 5,000 add-ons to customize browsing experience</span></strong></li>
<li><strong><span style="color:#666699;">And finally it has 14,000 improvements</span></strong></li>
<li><strong><span style="color:#666699;">I hope these features are sufficient....lol</span></strong></li>
</ul>
<p>Read the full article <a href="http://sachinkraj.wordpress.com/2008/06/11/firefox-3-coming-on-june-17/"><strong>here</strong></a>.</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox 3 - Coming on June 17 ]]></title>
<link>http://sachinkraj.wordpress.com/?p=318</link>
<pubDate>Tue, 10 Jun 2008 19:08:45 +0000</pubDate>
<dc:creator>Shubhamoy</dc:creator>
<guid>http://sachinkraj.wordpress.com/?p=318</guid>
<description><![CDATA[Hello Friends,
You will be amazed to know that our most lovable browser Mozilla Firefox&#8217;s Vers]]></description>
<content:encoded><![CDATA[<p>Hello Friends,</p>
<p>You will be amazed to know that our most lovable browser <strong>Mozilla Firefox's</strong> <strong>Version 3</strong>(or <strong>Gran Paradiso</strong>, its development name) is coming in few days(as told by Mozilla Engineers). So just hold your breath as the new <strong>Firefox</strong> comes. Its features are really astonishing. Let me tell you some of its features:</p>
<ul>
<li><strong><span style="color:#666699;">One-Click Bookmarking</span></strong></li>
<li><strong><span style="color:#666699;">Phishing and Malware Protection</span></strong></li>
<li><strong><span style="color:#666699;">Site ID info</span></strong></li>
<li><strong><span style="color:#666699;">Built-in spell checking</span></strong></li>
<li><strong><span style="color:#666699;">Session Restore and Full Zoom</span></strong></li>
<li><strong><span style="color:#666699;">And most shocking one, It has 5,000 add-ons to customize browsing experience</span></strong></li>
<li><strong><span style="color:#666699;">And finally it has 14,000 improvements</span></strong></li>
<li><strong><span style="color:#666699;">I hope these features are sufficient....lol</span></strong></li>
</ul>
<p>Do you know that <strong>Firefox</strong> has decided to create a <strong>GUINNESS WORLD RECORD</strong> by <strong>Most Software Downloaded in 24 hours</strong>. So wanna <strong>PLEDGE FOR IT</strong>. <br />
                                           <a title="Download Day 2008" href="http://www.spreadfirefox.com/node&#38;id=0&#38;t=264" target="_blank"><img src="http://www.spreadfirefox.com/sites/all/themes/spreadfirefox_RCS/images/download-day/buttons/en-US/180x150_02.png" border="0" alt="Download Day 2008" /></a></p>
<p>Click on the pic to go to the <strong>Spread Firefox</strong> page, even you can <a href="http://www.spreadfirefox.com/en-US/worldrecord"><strong>Click Here</strong></a> also.</p>
<p>If you wanna give it a try then here is the link to its download page(this is the link for Firefox 3 Release Candidate 2), <a href="http://www.mozilla.com/en-US/firefox/all-rc.html"><strong>Click Here</strong></a>, but before downloading it please read <a title="Known Issues" href="http://www.mozilla.com/en-US/firefox/3.0rc2/releasenotes/#issues"><strong>this</strong></a>.<strong> </strong>And do you know it comes in 45 different languages. Isn't it amazing! If you are new to <strong>Mozilla Firefox</strong>, then you can go for the stable version, i.e., 2.0.0.14. <a title="Firefox 2.0.0.14" href="http://www.mozilla.com/en-US/firefox/?from=getfirefox"><strong>Click Here</strong></a>.</p>
<p><strong><span style="text-decoration:underline;">Update:</span></strong></p>
<p>Firefox 3 is going to be released on 17th June 2008. So just few days to go :-D.</p>
<p><strong>Source:</strong> <a title="Firefox 3" href="http://developer.mozilla.org/devnews/index.php/2008/06/11/coming-tuesday-june-17th-firefox-3/" target="_blank"><strong>Mozilla Dev News</strong></a></p>
<p><strong><span style="text-decoration:underline;">Further Reading:</span></strong></p>
<ul>
<li>Firefox 3, on <strong><a href="http://en.wikipedia.org/wiki/Firefox_3#Version_3.0">Wikipedia</a></strong></li>
<li>Firefox 3, on <strong><a href="http://wiki.mozilla.org/Firefox3">Mozilla Wiki</a></strong></li>
<li>A review by <strong><a href="http://www.informationweek.com/news/internet/browsers/showArticle.jhtml?articleID=204200895">Information Week</a></strong></li>
<li>Another review at <strong><a href="http://www.wired.com/software/softwarereviews/news/2007/11/firefox3beta">Wired.com</a></strong></li>
<li>A detailed review at <strong><a href="http://mozillalinks.org/wp/2008/03/firefox-3-beta-4-review/">Mozilla Links</a></strong></li>
<li>Some screenshots at <a href="http://lifehacker.com/software/screenshot-tour/first-look-at-firefox-30-319968.php"><strong>Life Hacker</strong></a></li>
</ul>
<p> </p>
<p> </p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Speeding up Internet Explorer]]></title>
<link>http://shubhamoy.wordpress.com/?p=23</link>
<pubDate>Thu, 29 May 2008 10:19:22 +0000</pubDate>
<dc:creator>Shubhamoy</dc:creator>
<guid>http://shubhamoy.wordpress.com/?p=23</guid>
<description><![CDATA[Hello Friends,
Do you know that on an average nearly 25% users are using Internet Explorer as their ]]></description>
<content:encoded><![CDATA[<p>Hello Friends,</p>
<p>Do you know that on an average nearly 25% users are using Internet Explorer as their browser. So I thought to tell you a method to tweak Internet Explorer. Here I begin:</p>
<p>Read the full article <a href="http://sachinkraj.wordpress.com/2008/05/29/speeding-up-internet-explorer/"><strong>here</strong></a>.</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Legitimate Web Sites Serving Zero Day Flash Player Exploit]]></title>
<link>http://bardissi.wordpress.com/?p=411</link>
<pubDate>Wed, 28 May 2008 22:16:10 +0000</pubDate>
<dc:creator>bardissi</dc:creator>
<guid>http://bardissi.wordpress.com/?p=411</guid>
<description><![CDATA[Severity: High
28 May, 2008
Summary:

These vulnerabilities affect: Adobe Flash Player 9.0.124.0 and]]></description>
<content:encoded><![CDATA[<h3 style="margin:auto 0;"><span style="font-size:small;"><span style="font-family:Verdana;"><span>Severity: </span><span style="color:#ff0000;"><span class="style31"><span>High</span></span><span></span></span></span></span></h3>
<p><span style="font-size:x-small;font-family:Verdana;">28 May, 2008</span></p>
<h3 style="margin:auto 0;"><span><span style="font-size:small;"><span style="font-family:Verdana;">Summary:</span></span></span></h3>
<ul type="square">
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:&#34;">These vulnerabilities affect:</span></strong><span style="font-size:9pt;font-family:&#34;"> Adobe Flash Player 9.0.124.0 and earlier on Windows (potentially affects OS X, Unix, and Linux as well) </span></li>
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:&#34;">How an attacker exploits them:</span></strong><span style="font-size:9pt;font-family:&#34;"> By enticing one of your users into playing a maliciously crafted Flash (.SWF) file </span></li>
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:&#34;">Impact:</span></strong><span style="font-size:9pt;font-family:&#34;"> An attacker could execute code on the victim's computer, and take control of it </span></li>
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:&#34;">What to do:</span></strong><span style="font-size:9pt;font-family:&#34;"> Adobe hasn't released a patch yet; see the solution section below for workarounds </span></li>
</ul>
<h3 style="margin:auto 0;"><span><span style="font-size:small;"><span style="font-family:Verdana;">Exposure:</span></span></span></h3>
<p><span style="font-size:x-small;font-family:Verdana;">Adobe Flash Player displays interactive, animated web content called </span><a href="http://www.webopedia.com/TERM/F/Flash.html"><span style="font-size:x-small;color:#990000;font-family:Verdana;">Flash</span></a><span style="font-size:x-small;font-family:Verdana;">, often formatted as a Shockwave (.SWF) file. Adobe's Flash Player ships by default with many web browsers, including Internet Explorer (IE). It also runs on many operating systems.</span></p>
<p><span style="font-size:x-small;font-family:Verdana;">Late yesterday, </span><a href="http://www.symantec.com/security_response/threatcon/index.jsp"><span style="font-size:x-small;color:#990000;font-family:Verdana;">Symantec</span></a><span style="font-size:x-small;font-family:Verdana;">, SANS Internet Storm Center Handler's Diary [ </span><a href="http://isc.sans.org/diary.html?storyid=4465"><span style="font-size:x-small;color:#990000;font-family:Verdana;">1</span></a><span style="font-size:x-small;font-family:Verdana;"> / </span><a href="http://isc.sans.org/diary.html?storyid=4468"><span style="font-size:x-small;color:#990000;font-family:Verdana;">2</span></a><span style="font-size:x-small;font-family:Verdana;"> / </span><a href="http://isc.sans.org/diary.html?storyid=4474"><span style="font-size:x-small;color:#990000;font-family:Verdana;">3</span></a><span style="font-size:x-small;font-family:Verdana;"> ], and </span><a href="http://www.securityfocus.com/bid/29386/info"><span style="font-size:x-small;color:#990000;font-family:Verdana;">SecurityFocus</span></a><span style="font-size:x-small;font-family:Verdana;"> all warned of a serious zero day Flash Player vulnerability which they have found attackers exploiting in the wild. As of this writing, researchers do not know the technical details about this new vulnerability; they do know, however, that if one of your users downloads and plays a specially crafted Shockwave Flash (.SWF) file, an attacker could exploit the unpatched flaw to execute code on that user's computer, with that user's privileges. Since most Windows administrators grant their users local administrative privileges, an attacker could potentially exploit these flaws to gain complete control of a victim's computer. The malicious .SWF file could be hosted on a web site, sent via an HTML e-mail, or delivered in other ways via applications that embed Flash.</span></p>
<p><span style="font-size:x-small;font-family:Verdana;">According to the last </span><a href="http://www.securityfocus.com/bid/29386/exploit"><span style="font-size:x-small;color:#990000;font-family:Verdana;">update</span></a><span style="font-size:x-small;font-family:Verdana;"> from SecurityFocus, attackers are exploiting this zero day vulnerability in great numbers. They warn that attackers have injected this malicious .SWF exploit into approximately 20,000 legitimate web sites, using web-based attack techniques like those we recently described in our recent </span><a href="http://www.watchguard.com/education/radiofreesecurity.asp"><span style="font-size:x-small;color:#990000;font-family:Verdana;">Radio Free Security podcast</span></a><span style="font-size:x-small;font-family:Verdana;">.</span></p>
<p><span style="font-size:x-small;font-family:Verdana;">On the other hand, this morning Symantec updated their </span><a href="http://www.symantec.com/security_response/threatcon/index.jsp"><span style="font-size:x-small;color:#990000;font-family:Verdana;">Threatcon</span></a><span style="font-size:x-small;font-family:Verdana;"> information claiming this Flash Player vulnerability may not be as new as they originally thought. Their latest technical analysis reveals that the flaw appears similar to one Adobe has already patched. Even with that, Symantec has still observed this new exploit affecting <em>fully patched</em> versions of Adobe Flash Player. So, either this is a true zero day variant of the original flaw, or Adobe's patch is not working as reliably as it should. Regardless, if you allow Adobe Flash Player in your network, you should remain concerned about this new exploit and follow the workarounds suggested below.</span></p>
<h3 style="margin:auto 0;"><span><span style="font-size:small;"><span style="font-family:Verdana;">Solution Path:</span></span></span></h3>
<p><span style="font-size:x-small;font-family:Verdana;">Because researchers first found this vulnerability being exploited in the wild, Adobe has not had time to release a patch for Flash Player. Until they do, the following workarounds will mitigate the risk of this new exploit affecting your users:</span></p>
<ul type="square">
<li class="MsoNormal"><span style="font-size:9pt;font-family:&#34;">Internet Explorer (IE) users can set the killbit for Adobe's Flash Player. This prevents IE from playing any Flash content with the Adobe Flash Player. Bear in mind that this also prevents legitimate Flash content from playing. Refer to <a href="http://support.microsoft.com/kb/240797"><span style="color:#990000;">this Microsoft Knowledge Base article</span></a> for more details on how to set a killbit. Flash Player's CLSID is BD96C556-65A3-11D0-983A-00C04FC29E36. </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:&#34;">Firefox users should install the <a href="http://noscript.net/"><span style="color:#990000;">NoScript</span></a> extension. NoScript prevents web sites from running JavaScript, Java, Flash, or other executable web content by default. While NoScript does prevent legitimate web sites from executing scripts as well, you can easily add those trusted sites to your white list to allow them to run the content you need. </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:&#34;">Use a gateway device, like WatchGuard's Firebox products, to block .SWF files from entering your network. See below for more details. </span></li>
</ul>
<h4 style="margin:auto 0;"><span><span style="font-size:small;"><span style="font-family:Verdana;">For All WatchGuard Users:</span></span></span></h4>
<p><span style="font-size:x-small;font-family:Verdana;">Some of WatchGuard's Firebox models allow you to prevent your users from accessing Shockwave Flash files (.SWF) via the web (HTTP) or emails (SMTP, POP3). If you like, you can temporarily mitigate the risk of this vulnerability by blocking .SWF files using your Firebox's proxy services (video instructions below). Again, many web sites rely on Flash for interactive content, and blocking Flash prevents these sites from working properly. Note that many popular video streaming sites, such as YouTube and JibJab, deliver video using a Flash front end, so this technique may render many video web sites unusable. Nonetheless, with the severity of this zero day exploit, you may want to temporarily block all .SWF content until Adobe releases a patch.</span></p>
<p><span style="font-size:x-small;font-family:Verdana;">If you choose to block Flash content, follow the links below for video instructions on using your Firebox proxy's content blocking features to block .SWF files by their file extensions:</span></p>
<ul type="square">
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:&#34;">Firebox X Edge running 10.x</span></strong><span style="font-size:9pt;font-family:&#34;"> </span>
<ul type="square">
<li class="MsoNormal"><span style="font-size:9pt;font-family:&#34;">How do I block files with the FTP proxy? (Video, 2:30)<br />
<a href="https://www.watchguard.com/support/faqs/edge/10/FF_Edge_FTP.wmv" target="_blank"><span style="color:#990000;">Windows Media, 17.4MB</span></a>   /    <a href="https://www.watchguard.com/support/faqs/edge/10/FF_Edge_FTP.mov" target="_blank"><span style="color:#990000;">QuickTime, 11.8MB</span></a> </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:&#34;">How do I block files with the HTTP proxy? (Video, 2:52)<br />
<a href="https://www.watchguard.com/support/faqs/edge/10/FF_Edge_HTTP.wmv" target="_blank"><span style="color:#990000;">Windows Media, 32MB</span></a>   /    <a href="https://www.watchguard.com/support/faqs/edge/10/FF_Edge_HTTP.mov" target="_blank"><span style="color:#990000;">QuickTime, 28.6MB</span></a> </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:&#34;">How do I block files with the POP3 proxy? (Video, 2:35)<br />
<a href="https://www.watchguard.com/support/faqs/edge/10/FF_Edge_POP3.wmv" target="_blank"><span style="color:#990000;">Windows Media, 17.6MB</span></a>   /    <a href="https://www.watchguard.com/support/faqs/edge/10/FF_Edge_POP3.mov" target="_blank"><span style="color:#990000;">QuickTime, 16.5MB</span></a> </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:&#34;">How do I block files with the SMTP proxy? (Video, 2:18)<br />
<a href="https://www.watchguard.com/support/faqs/edge/10/FF_Edge_SMTP.wmv" target="_blank"><span style="color:#990000;">Windows Media, 12.2MB</span></a>   /    <a href="https://www.watchguard.com/support/faqs/edge/10/FF_Edge_SMTP.mov" target="_blank"><span style="color:#990000;">QuickTime, 9.1MB</span></a> </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:&#34;"> </span></li>
</ul>
</li>
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:&#34;">Firebox X Core and X Peak running Fireware 10.x</span></strong><span style="font-size:9pt;font-family:&#34;"> </span>
<ul type="square">
<li class="MsoNormal"><span style="font-size:9pt;font-family:&#34;">How do I block files with the FTP proxy? (Video, 2:30)<br />
<a href="https://www.watchguard.com/support/faqs/fireware/10/FF_Fireware_FTP.wmv" target="_blank"><span style="color:#990000;">Windows Media, 25.2MB</span></a>   /    <a href="https://www.watchguard.com/support/faqs/fireware/10/FF_Fireware_FTP.mov" target="_blank"><span style="color:#990000;">QuickTime, 9.1MB</span></a> </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:&#34;">How do I block files with the HTTP proxy? (Video, 2:52)<br />
<a href="https://www.watchguard.com/support/faqs/fireware/10/FF_Fireware_HTTP.wmv" target="_blank"><span style="color:#990000;">Windows Media, 38.2MB</span></a>   /    <a href="https://www.watchguard.com/support/faqs/fireware/10/FF_Fireware_HTTP.mov" target="_blank"><span style="color:#990000;">QuickTime, 10.7MB</span></a> </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:&#34;">How do I block files with the POP3 proxy? (Video, 2:35)<br />
<a href="https://www.watchguard.com/support/faqs/fireware/10/FF_Fireware_POP3.wmv" target="_blank"><span style="color:#990000;">Windows Media, 23.2MB</span></a>   /    <a href="https://www.watchguard.com/support/faqs/fireware/10/FF_Fireware_POP3.mov" target="_blank"><span style="color:#990000;">QuickTime, 10.1MB</span></a> </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:&#34;">How do I block files with the SMTP proxy? (Video, 2:18)<br />
<a href="https://www.watchguard.com/support/faqs/fireware/10/FF_Fireware_SMTP.wmv" target="_blank"><span style="color:#990000;">Windows Media, 25.6MB</span></a>   /    <a href="https://www.watchguard.com/support/faqs/fireware/10/FF_Fireware_SMTP.mov" target="_blank"><span style="color:#990000;">QuickTime, 9.0MB</span></a> </span></li>
</ul>
</li>
</ul>
<h3 style="margin:auto 0;"><span><span style="font-size:small;"><span style="font-family:Verdana;">Status:</span></span></span></h3>
<p><span style="font-size:x-small;font-family:Verdana;">Adobe has not had time to release a patch yet. Apply the workarounds described above.</span></p>
<h3 style="margin:auto 0;"><span><span style="font-size:small;"><span style="font-family:Verdana;">References:</span></span></span></h3>
<ul type="square">
<li class="MsoNormal"><span style="font-size:9pt;font-family:&#34;">SANS Internet Storm Center Handler's Diary Entries: </span>
<ul type="square">
<li class="MsoNormal"><span style="font-size:9pt;font-family:&#34;"><a href="http://isc.sans.org/diary.html?storyid=4465"><span style="color:#990000;">Zero Day SWF Entry 1</span></a> </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:&#34;"><a href="http://isc.sans.org/diary.html?storyid=4468"><span style="color:#990000;">Zero Day SWF Entry 2</span></a> </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:&#34;"><a href="http://isc.sans.org/diary.html?storyid=4474"><span style="color:#990000;">Zero Day SWF Entry 3</span></a> </span></li>
</ul>
</li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:&#34;"><a href="http://www.securityfocus.com/bid/29386/info"><span style="color:#990000;">Symantec's SecurityFocus Advisory</span></a> </span></li>
</ul>
<p><span style="font-size:9pt;color:black;font-family:&#34;"><a href="http://www.symantec.com/security_response/threatcon/index.jsp"><span style="color:#990000;">Symantec's Threatcon Advisory</span></a></span></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Safari: First Impressions]]></title>
<link>http://kristianoye.wordpress.com/?p=125</link>
<pubDate>Mon, 26 May 2008 20:59:54 +0000</pubDate>
<dc:creator>kristianoye</dc:creator>
<guid>http://kristianoye.wordpress.com/?p=125</guid>
<description><![CDATA[I have started to work on my social networking site again and so I have been downloading and trying ]]></description>
<content:encoded><![CDATA[<p>I have started to work on my social networking site again and so I have been downloading and trying out different web browsers for compatibility reasons.  So far, the site works well with Firefox, Internet Explorer, and Konqueror (Linux/KDE browser).  The only major browser I was unsure about was Apple's Safari.</p>
<p>"Thankfully," Apple has released their Safari browser to the Windows platform.  My first computer was an Apple, but I have no special place in my heart for the company or their religion.    I decided I should download the browser and give it a whirl.</p>
<p>Safari started up pretty quick and it seems to render pages pretty fast, but thirty seconds after logging into my site I realized I already had a number of issues to try and fix in order to support this browser.  My third party WYSIWYG editor was having issues (e.g. would not start).  It was a JavaScript issue.  I figured that would be easy to troubleshoot.  Oh, wait, Safari doesn't have a standard JavaScript debugger?  Wait, no DOM Inspector, either?  WTF?!</p>
<p>Now I have spent a couple of hours trying to find documentation on how to develop using Safari and so far I am SOL.  I have found plenty of documentation on how I <em>should</em> be able to turn on JavaScript debugging, but so far it hasn't worked.  I have slapped the following two lines in just about every configuration file I can think of (per the on-line docs) and still no luck.</p>
<p>&#60;key&#62;IncludeDebugMenu&#60;/key&#62;<br />
&#60;true/&#62;</p>
<p>[Another jab: What is up with this ridiculous XML schema in the "plist" files?]</p>
<p>Hmm.  Now I am pissed.  So what are my first impressions?  Not good!  First off, Apple insisting on using its own Widget set for the UI is annoying.  Second, the standard tools I would expect to find in a browser are not present or flat out do not work. Also, if you are going to put in debugging functionality, why not provide controls for turning it off and on?  Why make a person edit configuration files manually in order to enable/disable features?  And if you DO insist on making a person manually edit files, make sure your on-line docs are up-to-date.</p>
<p>To sum up: sure, the browser loads fast and renders quick, but if I can't troubleshoot my code in order to support it, or, if features found in other browsers do not work, why would I want to bother?</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Safari For Windows]]></title>
<link>http://ygpintermahbeda.wordpress.com/?p=14</link>
<pubDate>Sun, 18 May 2008 09:35:16 +0000</pubDate>
<dc:creator>-rizuki-</dc:creator>
<guid>http://ygpintermahbeda.wordpress.com/?p=14</guid>
<description><![CDATA[Sebenernya sih, udah lumayan lama wa tau kalo Apple ngeluarin browser buat Windows®.  Waktu itu se]]></description>
<content:encoded><![CDATA[<p>Sebenernya sih, udah lumayan lama wa tau kalo Apple ngeluarin browser buat Windows®.  Waktu itu sech nyobain Apple Safari for Windows versi Beta, tapi bujubuset, buggy-nya keterlaluan banget, kayak bukan Beta Release, tapi Alpha! moso lagi browsing tiba-tiba crash.  Langsung ilfil deh ama browser yang satu ini, padahal udah demen tuh.. dari eye-catchy nya.</p>
<p>But itu dulu, tadi siang, iseng nyobain Safari lagi .. Udah final release cuy, download 'n install, jajal deh.  Buggy-nya ilang tuh, udah pada di fix kali yah .. langsung demen ama ni browser ... hehehe.. :D</p>
<p>Kesan pertama: view area-nya luas banget, mungkin karena toolbar dan statusbar-nya dibikin simple, jadi luas banget view area-nya.  Fitur font-smoothing, enak banget diliat di layar LCD, <em>konon katanya</em> ini si Safari kecepatan render-nya hampir sama kayak Opera, tapi wa gak ngerasa juga sih. Dari letak menubar 'n Preference, emang bener ini keturunan Gecko Engine yang di customize sama tim Apple. Here's some SS.. </p>
<p> (klik buat diperbesar)<br />
<a href="http://img228.imageshack.us/my.php?image=youtubery8.png" target="_blank"><img src="http://img228.imageshack.us/img228/2517/youtubery8.th.png" border="0" alt="Free Image Hosting at www.ImageShack.us" /></a><br />
Resource Consumption - Multi-tabs + Video streaming (YouTube)</p>
<p><a href="http://img207.imageshack.us/my.php?image=browserinfonz7.jpg" target="_blank"><img src="http://img207.imageshack.us/img207/9493/browserinfonz7.th.jpg" border="0" alt="Free Image Hosting at www.ImageShack.us" /></a><br />
Browser Info, Resource Consumption @Multi Tabs Idle</p>
<p>Hmmm.. mayan juga yach, makan CPU + Memory resourcenya, but sebanding dengan fitur-fitur yang ditawarin.  Minus point dari Safari itu, ya plugin-nya belum sebanyak kompetitornya, apa lagi buat plugin buat filter ads-nya belum ada. , I'll keep go with Safari .. :p</p>
<p><a href="http://www.apple.com/safari" target="_blank">Download</a></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Safari?]]></title>
<link>http://charliestransmission.wordpress.com/?p=12</link>
<pubDate>Sun, 27 Apr 2008 21:47:19 +0000</pubDate>
<dc:creator>charliestransmission</dc:creator>
<guid>http://charliestransmission.wordpress.com/?p=12</guid>
<description><![CDATA[I downloaded Safari onto my VIsta as it makes me feel like I have a Mac&#8230; Yeah its good and all]]></description>
<content:encoded><![CDATA[<p>I downloaded Safari onto my VIsta as it makes me feel like I have a Mac... Yeah its good and all with quick loading time, hand favourites toolbar and other random stuff but It does not let me put paragraphs into here. Does Apple have an ongoing hate of WordPress. I only want paragraphs! </p>
<p>It also doesn't like my Non-American spelt words (eg. favourite - thinks it should be spelt favorite) </p>
<p>I shall blog about my day tomorrow as I have more time but now I am off to bed!</p>
<p> </p>
<p> </p>
<p>PS. After publishing this post the paragraphs have decided to work :D</p>
<p> </p>
<p> </p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[About the security content of Safari 3.1.1]]></title>
<link>http://marcodifresco.wordpress.com/?p=47</link>
<pubDate>Thu, 17 Apr 2008 18:00:40 +0000</pubDate>
<dc:creator>Marco Di Fresco</dc:creator>
<guid>http://marcodifresco.wordpress.com/?p=47</guid>
<description><![CDATA[Source http://support.apple.com/kb/HT1467

Summary
This document describes the security content of S]]></description>
<content:encoded><![CDATA[<p>Source <a href="http://support.apple.com/kb/HT1467" target="_blank">http://support.apple.com/kb/HT1467</a></p>
<blockquote>
<h2>Summary</h2>
<p>This document describes the security content of Safari 3.1.1, which can be downloaded and installed via <a href="http://docs.info.apple.com/article.html?artnum=106704">Software Update</a> preferences, or from <a href="http://www.apple.com/support/downloads/">Apple Downloads</a>.<!--more--></p>
<p>For the protection of our customers, Apple does not disclose, discuss, or confirm security issues until a full investigation has occurred and any necessary patches or releases are available. To learn more about Apple Product Security, see the <a href="http://www.apple.com/support/security/">Apple Product Security</a> website.</p>
<p>For information about the Apple Product Security PGP Key, see "<a href="http://docs.info.apple.com/article.html?artnum=25314">How to use the Apple Product Security PGP Key</a>."</p>
<p>Where possible, <a href="http://cve.mitre.org/about/">CVE IDs</a> are used to reference the vulnerabilities for further information.</p>
<p>To learn about other Security Updates, see "<a href="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</a>."</p>
<h2>Products Affected</h2>
<p>Safari 3 (Windows), Security, Safari 3.1</p>
<h4><span><span>Safari 3.1.1</span></span></h4>
<ul type="circle">
<li><strong>Safari</strong><br />
CVE-ID: CVE-2007-2398<br />
Available for: Windows XP or Vista<br />
Impact: A maliciously crafted website may control the contents of the address bar<br />
Description: A timing issue in Safari 3.1 allows a web page to change the contents of the address bar without loading the contents of the corresponding page. This could be used to spoof the contents of a legitimate site, allowing user credentials or other information to be gathered. This issue was addressed in Safari Beta 3.0.2, but reintroduced in Safari 3.1. This update addresses the issue by restoring the address bar contents if a request for a new web page is terminated. This issue does not affect Mac OS X systems.</li>
</ul>
<ul type="circle">
<li><strong>Safari</strong><br />
CVE-ID: CVE-2008-1024<br />
Available for: Windows XP or Vista<br />
Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution<br />
Description: A memory corruption issue exists in Safari's file downloading. By enticing a user to download a file with a maliciously crafted name, an attacker may cause an unexpected application termination or arbitrary code execution. This update addresses the issue through improved handling of file downloads. This issue does not affect Mac OS X systems.</li>
</ul>
<ul type="circle">
<li><strong>WebKit</strong><br />
CVE-ID: CVE-2008-1025<br />
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.2, Mac OS X Server v10.5.2, Windows XP or Vista<br />
Impact: Visiting a malicious website may result in cross-site scripting<br />
Description: An issue exists in WebKi's handling of URLs containing a colon character in the host name. Opening a maliciously crafted URL may lead to a cross-site scripting attack. This update addresses the issue through improved handling of URLs. Credit to Robert Swiecki of Google Information Security Team and David Bloom for reporting this issue.</li>
</ul>
<ul type="circle">
<li><strong>WebKit</strong><br />
CVE-ID: CVE-2008-1026<br />
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.2, Mac OS X Server v10.5.2, Windows XP or Vista<br />
Impact: Viewing a maliciously crafted web page may lead to an unexpected application termination or arbitrary code execution<br />
Description: A heap buffer overflow exists in WebKit's handling of JavaScript regular expressions. The issue may be triggered via JavaScript when processing regular expressions with large, nested repetition counts. This may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation of JavaScript regular expressions. Credit to Charlie Miller for reporting these issues.</li>
</ul>
</blockquote>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Safari Vulnerabilities Allow Attackers to Execute Code]]></title>
<link>http://bardissi.wordpress.com/?p=392</link>
<pubDate>Thu, 17 Apr 2008 14:35:25 +0000</pubDate>
<dc:creator>bardissi</dc:creator>
<guid>http://bardissi.wordpress.com/?p=392</guid>
<description><![CDATA[Severity: Medium
16 April, 2008
Summary:

These vulnerabilities affect: Safari 3 for OS X (and Windo]]></description>
<content:encoded><![CDATA[<h3 style="margin:auto 0;"><span><span style="font-size:x-small;"><span style="font-family:Verdana;">Severity: <span class="style31">Medium</span></span></span></span></h3>
<p><span style="font-size:xx-small;font-family:Verdana;">16 April, 2008</span></p>
<h3 style="margin:auto 0;"><span><span style="font-size:x-small;"><span style="font-family:Verdana;">Summary:</span></span></span></h3>
<ul type="square">
<li class="MsoNormal"><strong><span style="font-size:7pt;font-family:&#34;">These vulnerabilities affect:</span></strong><span style="font-size:7pt;font-family:&#34;"> Safari 3 for OS X (and Windows) </span></li>
<li class="MsoNormal"><strong><span style="font-size:7pt;font-family:&#34;">How an attacker exploits them:</span></strong><span style="font-size:7pt;font-family:&#34;"> By enticing one of your users to a malicious web page </span></li>
<li class="MsoNormal"><strong><span style="font-size:7pt;font-family:&#34;">Impact:</span></strong><span style="font-size:7pt;font-family:&#34;"> Numerous flaws, various results; in the worst case, an attacker could execute code on the victim's computer </span></li>
<li class="MsoNormal"><strong><span style="font-size:7pt;font-family:&#34;">What to do:</span></strong><span style="font-size:7pt;font-family:&#34;"> Update to Safari 3.1.1 at your earliest convenience </span></li>
</ul>
<h3 style="margin:auto 0;"><span><span style="font-size:x-small;"><span style="font-family:Verdana;">Exposure:</span></span></span></h3>
<p><span style="font-size:xx-small;font-family:Verdana;">Safari is the default web browser that ships with OS X. Recently, Apple also released Safari for Windows, </span><a href="http://www.watchguard.com/RSS/showarticle.aspx?pack=RSS.Apple.SU"><span style="font-size:xx-small;color:#990000;font-family:Verdana;">pushing</span></a><span style="font-size:xx-small;font-family:Verdana;"> it to Quicktime and iTunes users via Apple Software Update.</span></p>
<p><span style="font-size:xx-small;font-family:Verdana;">Today, Apple released an </span><a href="http://support.apple.com/kb/HT1467"><span style="font-size:xx-small;color:#990000;font-family:Verdana;">advisory</span></a><span style="font-size:xx-small;font-family:Verdana;"> describing four vulnerabilities that affect Safari, and components that ship with it. The flaws affect both the OS X and Windows versions of Safari. The worst of these vulnerabilities potentially allows attackers to execute malicious code on your Safari user's machines. If you use Safari in your network -- whether on a PC or Mac -- you should update to version 3.1.1 at your earliest convenience. Some of the fixed vulnerabilities include:</span></p>
<ul type="square">
<li class="MsoNormal"><strong><span style="font-size:7pt;font-family:&#34;">WebKit buffer overflow vulnerability. </span></strong><span style="font-size:7pt;font-family:&#34;"><a href="http://developer.apple.com/opensource/internet/webkit.html"><span style="color:#990000;">WebKit</span></a> is the web browser engine Safari uses on OS X machines. WebKit suffers from a <a href="http://www.watchguard.com/glossary/b.asp#buffer_overflow"><span style="color:#990000;">buffer overflow vulnerability</span></a> involving the way it handles <a href="http://en.wikipedia.org/wiki/Javascript"><span style="color:#990000;">JavaScript</span></a> <a href="http://en.wikipedia.org/wiki/Regular_expressions"><span style="color:#990000;">regular expressions</span></a>. By luring one of your users to a malicious web page, an attacker could exploit this flaw to execute code on your user's computer with your user's privileges. Since OS X users don't have administrative privileges by default, an attacker wouldn't be able to exploit this flaw to gain complete control of their machines without significant user interaction; he could still, however, exploit this flaw to do anything the victimized user could do. </span></li>
</ul>
<ul type="square">
<li class="MsoNormal"><strong><span style="font-size:7pt;font-family:&#34;">WebKit cross-site scripting vulnerability.</span></strong><span style="font-size:7pt;font-family:&#34;"> WebKit also suffers from a <a href="http://www.watchguard.com/glossary/c.asp#XSS"><span style="color:#990000;">Cross-Site Scripting (XSS)</span></a> vulnerability involving the way it handles <a href="http://www.watchguard.com/glossary/u.asp#URL"><span style="color:#990000;">URLs</span></a> containing the colon character in a host name. By enticing one of your users into clicking a specially crafted link, an attacker could exploit this flaw to execute scripts on that user's computer under the context of another legitimate site which your user trusts. For a more general explanation of XSS attacks, see our article <a href="http://www.watchguard.com/archive/showhtml.asp?pack=135142"><span style="color:#990000;">"Anatomy of a Cross-Site Scripting Attack."</span></a> </span></li>
</ul>
<p><span style="font-size:xx-small;font-family:Verdana;">Apple's alert also covers two vulnerabilities that affect the Windows version of Safari. By enticing one of your users to a malicious web site, an attacker could exploit the worst of these two flaws to execute code on that user's computer, potentially gaining control of it. However, we suspect few Windows users actually browse with Safari, so these flaws probably pose little risk to Windows users.</span></p>
<h3 style="margin:auto 0;"><span><span style="font-size:x-small;"><span style="font-family:Verdana;">Solution Path:</span></span></span></h3>
<p><span style="font-size:xx-small;font-family:Verdana;">Apple has release Safari 3.1.1 for OS X and Windows. If you use Safari in your network, you should </span><a href="http://www.apple.com/safari/download/"><span style="font-size:xx-small;color:#990000;font-family:Verdana;">download</span></a><span style="font-size:xx-small;font-family:Verdana;"> and install this update at your earliest convenience. </span></p>
<p><em><span style="font-size:xx-small;font-family:Verdana;">Note: You can also use Apple and OS X's Software Update utility to install Safari updates automatically.</span></em></p>
<h3 style="margin:auto 0;"><span><span style="font-size:x-small;"><span style="font-family:Verdana;">For All WatchGuard Users:</span></span></span></h3>
<p><span style="font-size:xx-small;font-family:Verdana;">These attacks travel as normal-looking HTTP traffic, which you must allow if your network users need to access the World Wide Web. Therefore, the patches above are your best solution.</span></p>
<h3 style="margin:auto 0;"><span><span style="font-size:x-small;"><span style="font-family:Verdana;">Status:</span></span></span></h3>
<p><span style="font-size:xx-small;font-family:Verdana;">Apple released Safari 3.1.1 to correct these issues.</span></p>
<h3 style="margin:auto 0;"><span><span style="font-size:x-small;"><span style="font-family:Verdana;">References:</span></span></span></h3>
<ul type="square">
<li class="MsoNormal"><span style="font-size:7pt;font-family:&#34;"><a href="http://support.apple.com/kb/HT1467"><span style="color:#990000;">Apple's Safari 3.1.1 Advisory</span></a> </span></li>
</ul>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Fixes Eleven Security Holes in QuickTime]]></title>
<link>http://bardissi.wordpress.com/2008/04/04/apple-fixes-eleven-security-holes-in-quicktime/</link>
<pubDate>Fri, 04 Apr 2008 10:25:54 +0000</pubDate>
<dc:creator>bardissi</dc:creator>
<guid>http://bardissi.wordpress.com/2008/04/04/apple-fixes-eleven-security-holes-in-quicktime/</guid>
<description><![CDATA[Severity: High
3 April, 2008
Summary:

This vulnerability affects: QuickTime 7.4.x for Mac and PC (a]]></description>
<content:encoded><![CDATA[<h3>Severity: High</h3>
<p>3 April, 2008</p>
<h3>Summary:</h3>
<ul>
<li><strong>This vulnerability affects:</strong> QuickTime 7.4.x for Mac and PC (and possibly earlier versions)</li>
<li><strong>How an attacker exploits it:</strong> Multiple methods of attack; in the most common, users are enticed to download and play a malicious movie or image in QuickTime</li>
<li><strong>Impact:</strong> Various results; in the worst case, an attacker executes code on your user's computer, potentially gaining complete control of it</li>
<li><strong>What to do:</strong> If you allow QuickTime (or iTunes), upgrade to 7.4.5 -- otherwise, remove these applications from your company's computers</li>
</ul>
<h3>Exposure:</h3>
<p>Today, Apple released an <a target="_blank" href="http://remote.bardissi.net/exchweb/bin/redir.asp?URL=http://support.apple.com/kb/HT1241"><font color="#990000">alert</font></a> fixing eleven vulnerabilities in their popular media player application, QuickTime. (Current versions of iTunes also ship with QuickTime; if your users have iTunes, they most likely have QuickTime.) These applications run on Windows and Macintosh computers, and both platforms are susceptible to exploitation of these security flaws. Apple's alert specifies Vista and XP SP2 as the vulnerable versions of Windows.</p>
<p>The vulnerabilities relate to different processes in QuickTime. For example: How it opens a picture file, how it displays movie files, how it handles a movie's media tracks, and so on. Some of these vulnerabilities allow attackers to execute any code they choose on your OS X machines, so we rate this update Critical. If you allow QuickTime, apply the update as soon as you can. Some of the vulnerabilities fixed include:</p>
<ul>
<li><strong>Multiple movie handling code execution vulnerabilities. </strong>QuickTime suffers from five vulnerabilities (mostly <a target="_blank" href="http://remote.bardissi.net/exchweb/bin/redir.asp?URL=http://www.webopedia.com/TERM/b/buffer_overflow.html"><font color="#990000">buffer overflow flaws</font></a>) involving the way it handles opening movie files. While the vulnerabilities differ technically, they all share the same scope and impact. If an attacker can get one of your users to open a maliciously crafted movie, he could trigger any of these flaws to execute code on your user's computer, with the same privileges and permissions your user has.</li>
</ul>
<ul>
<li><strong>Multiple image handling code execution vulnerabilities. </strong>QuickTime suffers from three buffer overflow vulnerabilities involving the way it handles .PICT image files. Like the movie flaws above, these three vulnerabilities differ technically but share the same scope and impact. By enticing one of your users to open a maliciously crafted .PICT image in QuickTime, an attacker could exploit any of these flaws to execute code on your user's Mac, with that user's privileges.</li>
</ul>
<ul>
<li><strong>VR Movie buffer overflow vulnerability. </strong>Quicktime supports <a target="_blank" href="http://remote.bardissi.net/exchweb/bin/redir.asp?URL=http://en.wikipedia.org/wiki/Quicktime_vr"><font color="#990000">QuickTime Virtual Reality (VR)</font></a>, or QTVR image files, which are panoramic images stitched together into one special image file which QuickTime allows you to explore in simulated 3-D. Unfortunately, QuickTime suffers from a buffer overflow vulnerability involving the way it handles a specially crafted QTVR image. If an attacker lures one of your users into viewing a malicious QTVR image, he could exploit this flaw to execute code on that user's computer, with that user's privileges.</li>
</ul>
<p>The remaining flaws in Apple's QuickTime alert include another code execution flaw in addition to those described above, and an information disclosure vulnerability. If you'd like to know more about any of these QuickTime flaws, refer to <a target="_blank" href="http://remote.bardissi.net/exchweb/bin/redir.asp?URL=http://support.apple.com/kb/HT1241"><font color="#990000">Apple's alert</font></a>.</p>
<h3>Solution Path:</h3>
<p>Apple has released QuickTime version 7.4.5 to correct these flaws. If you allow QuickTime or iTunes in your network (or suspect that your users have installed them), we recommend that users either remove the applications or install <a target="_blank" href="http://remote.bardissi.net/exchweb/bin/redir.asp?URL=http://www.apple.com/quicktime/download/"><font color="#990000">version 7.4.5</font></a>.</p>
<p>The latest versions of QuickTime and iTunes for Windows ship with Apple Software Update. Apple Software Update automatically detects updates such as this one for QuickTime, and then informs you, so that you can install it as soon as possible. If you choose to allow QuickTime or iTunes in your network, we recommend you set Apple Software Update to check for new updates daily and allow it to assist you in keeping your Apple software current.</p>
<p><strong>Notes:</strong> Apple recently used Software Update to push Safari 3.1 onto Windows computers that did not have Safari installed. If you do not want to install Safari on your computers, be sure to uncheck the Safari 3.1 update option. Also, Apple ships QuickTime combined with iTunes by default. If you do not want iTunes, there is a <a target="_blank" href="http://remote.bardissi.net/exchweb/bin/redir.asp?URL=http://www.apple.com/quicktime/download/standalone.html"><font color="#990000">standalone version of QuickTime</font></a> which you can download instead.</p>
<h4>For All Users:</h4>
<p>These attacks rely on getting one of your users to download and open any of several different QuickTime movie or image file types. Many of these multimedia formats have legitimate business uses and should not be blocked categorically at your firewall. Unless you want to block all of the media types that QuickTime supports, you should insist that users either remove QuickTime and iTunes, or install Apple's QuickTime update as soon as possible.</p>
<h3>Status:</h3>
<p>Apple released QuickTime 7.4.5, which fixes this issue.</p>
<h3>References:</h3>
<ul>
<li><a target="_blank" href="http://remote.bardissi.net/exchweb/bin/redir.asp?URL=http://support.apple.com/kb/HT1241"><font color="#990000">Apple's QuickTime alert</font></a></li>
<li><a target="_blank" href="http://remote.bardissi.net/exchweb/bin/redir.asp?URL=http://www.apple.com/support/downloads/"><font color="#990000">Apple software downloads</font></a></li>
<li><a target="_blank" href="http://remote.bardissi.net/exchweb/bin/redir.asp?URL=http://support.apple.com/kb/HT1222"><font color="#990000">Apple security updates</font></a></li>
</ul>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Mozilla Stomps Out Ten Security Vulnerabilities with Firefox 2.0.0.13]]></title>
<link>http://bardissi.wordpress.com/2008/03/28/mozilla-stomps-out-ten-security-vulnerabilities-with-firefox-20013/</link>
<pubDate>Fri, 28 Mar 2008 12:34:57 +0000</pubDate>
<dc:creator>bardissi</dc:creator>
<guid>http://bardissi.wordpress.com/2008/03/28/mozilla-stomps-out-ten-security-vulnerabilities-with-firefox-20013/</guid>
<description><![CDATA[Severity: Medium
27 March, 2008
Summary:

This vulnerability affects: Firefox 2.0.0.x for Windows, L]]></description>
<content:encoded><![CDATA[<h3><span><font size="3"><font face="Verdana">Severity: Medium</font></font></span></h3>
<p><font size="2" face="Verdana">27 March, 2008</font></p>
<h3><span><font size="3"><font face="Verdana">Summary:</font></font></span></h3>
<ul type="square">
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">This vulnerability affects:</span></strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';"> Firefox 2.0.0.x for Windows, Linux, and Macintosh </span></li>
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">How an attacker exploits it:</span></strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';"> Multiple vectors of attack, including enticing one of your users to visit a malicious web page </span></li>
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">Impact:</span></strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';"> Various results; in the worst case, attacker executes code on your user's computer, gaining complete control of it </span></li>
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">What to do:</span></strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';"> Upgrade to Firefox 2.0.0.13 </span></li>
</ul>
<h3><span><font size="3"><font face="Verdana">Exposure:</font></font></span></h3>
<p><font size="2" face="Verdana">Yesterday, the Mozilla Foundation released </font><a href="http://www.mozilla.com/en-US/firefox/"><font size="2" color="#990000" face="Verdana">Firefox 2.0.0.13</font></a><font size="2" face="Verdana">, fixing ten security vulnerabilities (based on </font><a href="http://cve.mitre.org/"><font size="2" color="#990000" face="Verdana">CVE-ID</font></a><font size="2" face="Verdana">s) in the popular web browser. We summarize three of the more critical vulnerabilities below:</font></p>
<ul type="square">
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">Memory corruption vulnerabilities (<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-15.html"><font color="#990000">2008-015</font></a>).</span></strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';"> Firefox suffers from several unspecified crash bugs, which corrupt memory. Mozilla presumes that, with enough effort, some of these memory corruption flaws could be exploited to run arbitrary code. To exploit these flaws, an attacker would first have to trick one of your users into visiting a maliciously crafted web page. If your user took the bait, the attacker could execute code on that user's machine, with that user's privileges. And if the user happened to be a local administrator or had root privileges, the attacker would gain total control of the victim's computer.<br />
<em>Mozilla Impact rating: </em><strong><i><span style="font-family:'Verdana','sans-serif';">Critical</span></i></strong> </span></li>
</ul>
<ul type="square">
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">JavaScript privilege elevation and code execution vulnerabilities (<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-14.html"><font color="#990000">2008-014</font></a>).</span></strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';"> Firefox suffers from various vulnerabilities involving the way it handles specially crafted JavaScript. By enticing one of your users to a web page containing malicious JavaScript, an attacker could exploit these flaws to <a href="http://www.watchguard.com/glossary/e.asp#elevation"><font color="#990000">elevate privileges</font></a>, execute a <a href="http://www.watchguard.com/glossary/c.asp#XSS"><font color="#990000">Cross-Site Scripting (XSS)</font></a> attack, or even execute code on your user's machine, with your user's privileges. Depending on your user's level of privilege, an attacker could exploit this flaw to gain complete control of the user's computer.<i><br />
<em>Mozilla Impact rating: </em><strong><span style="font-family:'Verdana','sans-serif';">Critical</span></strong></i> </span></li>
</ul>
<ul type="square">
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">Java socket connection vulnerability (<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-18.html"><font color="#990000">2008-018</font></a>).</span></strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';"> Mozilla's alert describes a security vulnerability that Sun has recently <a href="https://www.watchguard.com/archive/showhtml.asp?pack=66384"><font color="#990000">fixed</font></a>. By enticing one of your users to a malicious web site containing specially crafted Java code, an attacker could exploit this JRE vulnerability to gain direct access to ports on your computer. Even if your firewall blocks access to those particular ports, the malicious web site's code -- which would travel over port 80 -- could locally access any port on your user's computer, bypassing your firewall policies. If you've already applied the JRE update we mentioned in our previous <a href="https://www.watchguard.com/archive/showhtml.asp?pack=66384"><font color="#990000">JRE alert</font></a>, this vulnerability won't affect you; for those who haven't installed the JRE update yet, Mozilla's update patches this flaw on Firefox's side.<i><br />
<em>Mozilla Impact rating: </em><strong><span style="font-family:'Verdana','sans-serif';">High</span></strong></i> </span></li>
</ul>
<p><font size="2" face="Verdana">The remaining vulnerabilities include popup spoofing, information disclosure, and </font><a href="http://en.wikipedia.org/wiki/Cross-site_request_forgery"><font size="2" color="#990000" face="Verdana">Cross-Site Request Forgery (CSRF)</font></a><font size="2" face="Verdana"> flaws. If you'd like to know more about them, check out </font><a href="http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.13"><font size="2" color="#990000" face="Verdana">Firefox's known issues</font></a><font size="2" face="Verdana"> page. However, the vulnerabilities described above should be enough to convince you to upgrade your Firefox users to the fixed version at your earliest convenience.</font></p>
<h3><span><font size="3"><font face="Verdana">Solution Path:</font></font></span></h3>
<p><font size="2" face="Verdana">Mozilla has updated Firefox, correcting these security vulnerabilities. If you use Firefox in your network, we recommend that you download and deploy version 2.0.0.13 as soon as possible. Mozilla no longer supports the 1.5.x branch of Firefox; we recommend that 1.5.x users migrate to 2.0.0.13 now.</font></p>
<ul type="square">
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://download.mozilla.org/?product=firefox-2.0.0.13&#38;os=win&#38;lang=en-US"><font color="#990000">Windows</font></a> </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://download.mozilla.org/?product=firefox-2.0.0.13&#38;os=linux&#38;lang=en-US"><font color="#990000">Linux</font></a> </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://download.mozilla.org/?product=firefox-2.0.0.13&#38;os=osx&#38;lang=en-US"><font color="#990000">Mac OS X</font></a> </span></li>
</ul>
<p><font size="2"><strong><span style="font-family:'Verdana','sans-serif';">Note:</span></strong><font face="Verdana"> The latest versions of Firefox 2.0 automatically inform you when a Firefox update is available. We highly recommend you keep this feature enabled so that Firefox receives its updates as soon as Mozilla releases them. To verify that you have Firefox configured to automatically check for updates, click <strong><span style="font-family:'Verdana','sans-serif';">Tools =&#62; Options =&#62; Advanced</span></strong> tab<strong><span style="font-family:'Verdana','sans-serif';"> =&#62; Update</span></strong> tab. Make sure that "Firefox" is checked under "Automatically check for updates." In this menu, you can configure Firefox to always download and install any update, or only to inform the user that the update exists.</font></font></p>
<h3><span><font size="3"><font face="Verdana">For All WatchGuard Users:</font></font></span></h3>
<p><font size="2" face="Verdana">Some of these attacks arrive as normal-looking HTTP traffic, which you must allow through your firewall if your network users need to access the World Wide Web. Therefore, the patches above are your best solution.</font></p>
<h3><span><font size="3"><font face="Verdana">Status:</font></font></span></h3>
<p><font size="2" face="Verdana">The Mozilla Foundation has released Firefox 2.0.0.13, fixing these security issues.</font></p>
<h3><span><font size="3"><font face="Verdana">References:</font></font></span></h3>
<ul type="square">
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://www.mozilla.com/en-US/firefox/2.0.0.13/releasenotes/"><font color="#990000">Firefox 2.0.0.13 Release Notes</font></a> </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.13"><font color="#990000">Vulnerabilities Fixed in Firefox 2.0.0.13</font></a> </span></li>
</ul>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Safari es legal en Windows]]></title>
<link>http://tecnologiadehoy.wordpress.com/2008/03/28/safari-es-legal-en-windows/</link>
<pubDate>Fri, 28 Mar 2008 10:06:16 +0000</pubDate>
<dc:creator>igonzalezyauck</dc:creator>
<guid>http://tecnologiadehoy.wordpress.com/2008/03/28/safari-es-legal-en-windows/</guid>
<description><![CDATA[Una errata en la licencia de uso del nuevo Safari 3.1 para Windows ha hecho que muchos medios hayan ]]></description>
<content:encoded><![CDATA[<p><i>Una errata en la licencia de uso del nuevo Safari 3.1 para Windows ha hecho que muchos medios hayan comunicado erróneamente que podría existir un curioso problema legal con este navegador, pero no es así. De hecho, lo más importante no es este equívoco, sino el nuevo sistema de renderizado de fuentes.</i><!--more--></p>
<p>Mientras que en pasadas versiones del motor WebKi, Safari no mostraba bien las tipografías en Windows, la última versión del navegador de Apple ha incluido una importante mejora: soporte para el uso de <a href="http://webkit.org/blog/168/gdi-text-on-windows/" target="_blank">Windows GDI</a>, o lo que es lo mismo, no más problemas con las tipografías en sistemas Windows.</p>
<p>Este importante soporte ha sido ensombrecido por la polémica surgida a raíz de una frase mal expresada de la licencia de uso de Safari 3.1, que parecía especificar que era ilegal usar Safari en Windows, algo inexplicable que solo excluiría casos como ejecutarlo a través de BootCamp o de un programa de virtualización. Sin embargo, en Ars Technica se pusieron en contacto con los responsables de Apple, que poco después les confirmaron que, efectivamente, la licencia contenía un error.</p>
<h6>Fuente: www.theinquirer.es</h6>
<h6></h6>
]]></content:encoded>
</item>
<item>
<title><![CDATA[A rocky Windows trek for Apple's Safari browser ]]></title>
<link>http://mazaqah.wordpress.com/2008/03/27/a-rocky-windows-trek-for-apples-safari-browser/</link>
<pubDate>Thu, 27 Mar 2008 20:56:04 +0000</pubDate>
<dc:creator>muhammed ansari</dc:creator>
<guid>http://mazaqah.wordpress.com/2008/03/27/a-rocky-windows-trek-for-apples-safari-browser/</guid>
<description><![CDATA[The first problem for Safari 3.1, Apple&#8217;s new Web browser for Windows, was how it arrived on p]]></description>
<content:encoded><![CDATA[<p>The first problem for Safari 3.1, Apple's new Web browser for Windows, was how it arrived on people's computers. Last week millions who were only marginally connected to Apple -- because they'd downloaded iTunes -- were prompted to "update" to Safari, even though they'd never expressed an interest in the thing.</p>
<p>Apple's competitors in the browser market were naturally <a target="_blank" href="http://john.jubjubs.net/2008/03/21/apple-software-update/"><font color="#cc4400">not happy</font></a> with that move, which smacked of Microsoftian bundling. (Microsoft used its operating system monopoly to push browser software; now Apple is using its dominance in music to push browser software.)</p>
<p>But the outcry sparked by that move was just the start. Soon there was word of <a target="_blank" href="http://www.theregister.co.uk/2008/03/26/apple_safari_eula_paradox/"><font color="#cc4400">a snafu</font></a> in Apple's end-user license for the Windows Safari -- the fine print granted people the right to use the app only on "Apple-labeled" computers. Right: Safari for Windows was, by its own terms, illegal. (Apple has since <a target="_blank" href="http://www.macnn.com/articles/08/03/27/safari.license.changed/"><font color="#cc4400">updated the license.</font></a>)</p>
<p>There are also some reports of the thing <a target="_blank" href="http://discussions.apple.com/thread.jspa?threadID=1453407&#38;tstart=0"><font color="#cc4400">crashing,</font></a> and now there are security flaws, too. The tech security firm Secunia says it has found <a target="_blank" href="http://secunia.com/advisories/29483/"><font color="#cc4400">two "highly critical" holes</font></a> in Safari for Windows that allow untrusted Web sites to gain access to a user's system.</p>
<p>There are no known fixes for the holes yet, other than Secunia's advisory to refrain from browsing "untrusted Web sites" with Safari.</p>
<p>Not that other browsers don't suffer the same flaws, of course. But this was supposed to be the best browser in the world</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple aprende a 'sacanagem geral' com update/install meio forçado do Safari]]></title>
<link>http://snnangola.wordpress.com/?p=355</link>
<pubDate>Sat, 22 Mar 2008 11:29:26 +0000</pubDate>
<dc:creator>snnangola</dc:creator>
<guid>http://snnangola.wordpress.com/?p=355</guid>
<description><![CDATA[
A Apple nos ultimos tempos começa a mostrar a sua verdadeira face. Com sede de abocanhar mais algu]]></description>
<content:encoded><![CDATA[<p align="center"><img src="http://regmedia.co.uk/2007/06/13/safari_oh_dear.jpg" align="middle" height="417" width="549" /></p>
<p>A Apple nos ultimos tempos começa a mostrar a sua verdadeira face. Com sede de abocanhar mais alguns 'litros' na Web com o seu 'Fastest' navegador Safari, produziu um novo truque. No Update do Itunes (que nao é usado por pouca gente) e do QuickTime, a mesma <a href="http://www.news.com/8301-10784_3-9900456-7.html">propoe</a> o download do navegador Safari, que segundo ela é o mais rápido e facil de usar do mercado. E como nem todos usuarios sao como eu (brincadeirinha) que sabe o que quer, bom a ver vamos, vao mesmo clicar nas duas opções...</p>
<p align="center"><img src="http://i.i.com.com/cnwk.1d/i/bto/20080321/apple.JPG" align="middle" height="556" width="426" /></p>
<p>Quem nao gostou nada Mozilla, que a julgar pelas <a href="http://www.news.com/8301-10784_3-9901006-7.html">palavras</a> do seu CEO trata-se duma especie de jogo sujo da empresa de Jobs, um dos mais falados geeks do momento (ha que reconhece-lo).</p>
<p>Pois, e o Gates é que era o malandro. É pena que seja só estar lá em cima para entrar na sacanagem geral.</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple launchs Safari 3.1 Final for Windows]]></title>
<link>http://sourcezone.wordpress.com/?p=13</link>
<pubDate>Fri, 21 Mar 2008 14:41:26 +0000</pubDate>
<dc:creator>Max</dc:creator>
<guid>http://sourcezone.wordpress.com/?p=13</guid>
<description><![CDATA[I&#8217;ve been trying the earlier betas of Safari for Windows, but none of them have really convice]]></description>
<content:encoded><![CDATA[<p>I've been trying the earlier betas of Safari for Windows, but none of them have really conviced me at all, mainly because the majority of the websites I usually visit don't look right.</p>
<p>Nevertheless,  I downloaded and installed the new <a href="http://www.apple.com/safari/" title="Apple Safari 3.1" target="_blank">Apple Safari 3.1</a>, and to be honest, it surprised me.</p>
<p><img src="http://elcofrecito.com.ar/wp-content/uploads/2008/03/safari1.jpg" alt="Apple Safari 3.1" border="0" height="134" width="120" /></p>
<p>Unfortunately, it hangs up the first time I tried it.</p>
<p><!--more--><br />
Apart from that, then it works ok and there are some characteristics that really deserve some lines:</p>
<p>An interesting feature is <b>Private Browsing. </b>When activivated Safari doesn't store Google's search we made, cookies, history, downloads and forms data.<br />
<img src="http://elcofrecito.com.ar/wp-content/uploads/2008/03/safari-private-browsing.jpg" alt="Private brosing" height="265" width="420" /></p>
<p>Another feature, maybe not very useful but different,  is the possibility to change the size of the text areas. I haven't seen this in other browsers.<br />
<img src="http://elcofrecito.com.ar/wp-content/uploads/2008/03/resizable-textarea.jpg" alt="Resizable Textarea" height="299" width="500" /></p>
<p>The integrated RSS reader is quite good.<br />
<a href="http://elcofrecito.com.ar/wp-content/uploads/2008/03/rss-reader.jpg" target="_blank"><img src="http://elcofrecito.com.ar/wp-content/uploads/2008/03/rss-reader.thumbnail.jpg" alt="RSS Reader" height="99" width="128" /></a></p>
<p>Searching text in a web page with Safari it's very easy and clean. The search results are highlighted so you can find them quickly.<br />
<img src="http://elcofrecito.com.ar/wp-content/uploads/2008/03/safari-search.jpg" alt="Search" height="166" width="500" /></p>
<p>There are some other features that I haven't tried yet, such as <b>SnapBack</b>, bookmarks handling Itunes style and the form autocomplete.</p>
<p>Anyway, I think that which brower is best than the other is a matter of how comfortable do you feel working with it or which is easier to use.<br />
Personally, I use Firefox since its earlier releases, it seems to be fast, realible, it has the best tab browsing, although the memory use problem hasn't be solved yet.<br />
All in all, Apple Safari 3.1 has some innovations over the other competitors, but i think that it's too much saying that is the best browser in the world, as Apple said.</p>
<p>Or maybe is beacuse of her?<br />
<img src="http://elcofrecito.com.ar/wp-content/uploads/2008/03/safari_3d.jpg" alt="Safari Girl" height="417" width="352" /></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Gargantuan OS X Update Fixes Almost 100 Security Flaws]]></title>
<link>http://bardissi.wordpress.com/2008/03/18/gargantuan-os-x-update-fixes-almost-100-security-flaws/</link>
<pubDate>Wed, 19 Mar 2008 01:10:43 +0000</pubDate>
<dc:creator>bardissi</dc:creator>
<guid>http://bardissi.wordpress.com/2008/03/18/gargantuan-os-x-update-fixes-almost-100-security-flaws/</guid>
<description><![CDATA[Severity: High
18 March, 2008
Summary:

These vulnerabilities affect: OS X 10.4.x (Tiger) and OS X 1]]></description>
<content:encoded><![CDATA[<h3><font size="3"><font face="Verdana"><span>Severity: </span><font color="#ff0000"><span class="style11"><span>High</span></span><span></span></font></font></font></h3>
<p><font size="2" face="Verdana">18 March, 2008</font></p>
<h3><span><font size="3"><font face="Verdana">Summary:</font></font></span></h3>
<ul type="square">
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">These vulnerabilities affect:</span></strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';"> OS X 10.4.x (Tiger) and OS X 10.5.x (Leopard), both client and server versions </span></li>
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">How an attacker exploits them:</span></strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';"> Multiple vectors of attack, including enticing one of your users into visiting a URL or web site </span></li>
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">Impact:</span></strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';"> Various results; in the worst case, attacker executes code on your user's computer, potentially gaining complete of your user's computer </span></li>
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">What to do:</span></strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';"> OS X administrators should download, test and install Security Update 2008-002 </span></li>
</ul>
<h3><span><font size="3"><font face="Verdana">Exposure:</font></font></span></h3>
<p><font size="2" face="Verdana">Today, Apple released a </font><a href="http://docs.info.apple.com/article.html?artnum=307562"><font size="2" color="#990000" face="Verdana">security update</font></a><font size="2" face="Verdana"> fixing over 95 (number based on </font><a href="http://cve.mitre.org/"><font size="2" color="#990000" face="Verdana">CVE-ID</font></a><font size="2" face="Verdana">s) security issues in software packages that ship as part of OS X, including Apache, Preview, and Help Viewer. Some of these vulnerabilities allow attackers to execute any code they choose on your OS X machines, so we rate this update Critical. Apply it as soon as you can. Three of the vulnerabilities fixed include:</font></p>
<ul type="square">
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">Multiple integer overflow vulnerabilities in AppKit.</span></strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';"> AppKit is a OS X framework that helps developers implement graphical, event-driven user interfaces. According to Apple, Appkit suffers from <a href="http://en.wikipedia.org/wiki/Integer_overflow"><font color="#990000">integer overflow vulnerabilities</font></a> involving the way it parses something called a "serialized property list." By luring one of your users to a maliciously crafted web site, an attacker could exploit these flaws to execute code on your user's computer, with that user's privileges. The attacker could then leverage a separate vulnerability in AppKit -- also described in Apple's alert -- to gain system privilege, thus giving the attacker complete control of that user's Mac. </span></li>
</ul>
<ul type="square">
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">Foundation race condition vulnerability.</span></strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';"> Foundation is an OS X component that helps Safari handle web pages and <a href="http://www.watchguard.com/glossary/u.asp#URL"><font color="#990000">URL</font></a>s. According to Apple, Foundation suffers from a complicated <a href="http://en.wikipedia.org/wiki/Race_condition"><font color="#990000">race condition vulnerability</font></a>. If an attacker can entice one of your users into visiting a malicious web site, he could exploit this vulnerability to execute code on the user's computer, with that user's privileges. Furthermore, the attacker could then leverage other vulnerabilities described in Apple's alert to <a href="http://www.watchguard.com/glossary/e.asp#elevation"><font color="#990000">elevate privileges</font></a> and gain complete control of your user's computer. </span></li>
</ul>
<ul type="square">
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">Image Raw buffer overflow vulnerability. </span></strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">Image Raw is a component that allows OS X to handle the various <a href="http://en.wikipedia.org/wiki/Raw_image_format"><font color="#990000">RAW image formats</font></a> that some digital cameras support. Image Raw suffers from a <a href="http://www.webopedia.com/TERM/b/buffer_overflow.html"><font color="#990000">buffer overflow vulnerability</font></a> involving the way it handles specially malformed Adobe Digital Negative (DNG) image files. By enticing one of your users into viewing a malicious image, an attacker can exploit this flaw to execute code on that user's computer. By default, the attacker would only execute code with that user's privileges. However, he could then leverage another vulnerability -- also described in Apple's alert -- to gain complete control of your user's computer. </span></li>
</ul>
<p><font size="2" face="Verdana">Apple's alert includes many, many more flaws, including other code execution flaws in addition to those described above. The remaining vulnerabilities also include </font><a href="http://www.watchguard.com/glossary/d.asp#DoS"><font size="2" color="#990000" face="Verdana">Denial of Service (DoS)</font></a><font size="2" face="Verdana"> flaws, </font><a href="http://www.watchguard.com/glossary/e.asp#elevation_of_privilege"><font size="2" color="#990000" face="Verdana">elevation of privilege</font></a><font size="2" face="Verdana"> flaws, and information disclosure vulnerabilities, plus others. Components patched by this security update include:</font></p>
<table border="1" width="300" cellPadding="0" style="width:225pt;margin:auto auto auto 0.5in;" class="MsoNormalTable">
<tr>
<td width="140" style="width:105pt;background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">AFP Client</font></td>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">AFP Server</font></td>
</tr>
<tr>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">Apache</font></td>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">AppKit</font></td>
</tr>
<tr>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">Application Firewall</font></td>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">CFNetwork</font></td>
</tr>
<tr>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">ClamAV</font></td>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">CoreFoundation</font></td>
</tr>
<tr>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">Core Services</font></td>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">CUPS</font></td>
</tr>
<tr>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">curl</font></td>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">Emacs</font></td>
</tr>
<tr>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">file</font></td>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">Foundation</font></td>
</tr>
<tr>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">Help Viewer</font></td>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">Image Raw</font></td>
</tr>
<tr>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">Kerberos</font></td>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">libc</font></td>
</tr>
<tr>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">mDNSResponder</font></td>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">notifyd</font></td>
</tr>
<tr>
<td width="140" style="width:105pt;background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">OpenSSH</font></td>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">pax archive utility</font></td>
</tr>
<tr>
<td width="140" style="width:105pt;background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">PHP</font></td>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">Podcast Producer</font></td>
</tr>
<tr>
<td width="140" style="width:105pt;background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">Preview</font></td>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">Printing</font></td>
</tr>
<tr>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">System Configuration</font></td>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">UDF</font></td>
</tr>
<tr>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">Wiki Server</font></td>
<td style="background-color:transparent;border:#f0f0f0;padding:0.75pt;"><font size="2">X11</font></td>
</tr>
</table>
<p><font size="2" face="Verdana">Refer to </font><a href="http://docs.info.apple.com/article.html?artnum=307562"><font size="2" color="#990000" face="Verdana">Apple's alert</font></a><font size="2" face="Verdana"> for more details.</font></p>
<p><font size="2" face="Verdana">This is a huge update fixing many security vulnerabilities, some of which pose a critical security risk. If you manage OS X machines, we highly recommend you apply this update right away.</font></p>
<h3><span><font size="3"><font face="Verdana">Solution Path:</font></font></span></h3>
<p><font size="2" face="Verdana">Apple has released OS X Security Update 2008-002 to fix all these security issues. OS X administrators should download, test, and deploy Security Update 2008-002 as soon as they can.</font></p>
<ul type="square">
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&#38;cat=1&#38;platform=osx&#38;method=sa/SecUpd2008-002PPC.dmg"><font color="#990000">Security Update 2008-002 v1.0 (PPC)</font></a> </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18158&#38;cat=1&#38;platform=osx&#38;method=sa/SecUpd2008-002Univ.dmg"><font color="#990000">Security Update 2008-002 v1.0 (Universal)</font></a> </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18159&#38;cat=1&#38;platform=osx&#38;method=sa/SecUpd2008-002.dmg"><font color="#990000">Security Update 2008-002 v1.0 (Leopard)</font></a> </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18161&#38;cat=1&#38;platform=osx&#38;method=sa/SecUpdSrvr2008-002PPC.dmg"><font color="#990000">Security Update 2008-002 v1.0 Server (PPC)</font></a> </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18165&#38;cat=1&#38;platform=osx&#38;method=sa/SecUpdSrvr2008-002Univ.dmg"><font color="#990000">Security Update 2008-002 v1.0 Server (Universal)</font></a> </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18160&#38;cat=1&#38;platform=osx&#38;method=sa/SecUpdSrvr2008-002.dmg"><font color="#990000">Security Update 2008-002 v1.0 Server (Leopard)</font></a> </span></li>
</ul>
<p><font size="2" face="Verdana">Note: If you have trouble figuring out which of these patches corresponds to your version of OS X, we recommend you let OS X's Software Update utility pick the correct update for you automatically.</font></p>
<h3><span><font size="3"><font face="Verdana">For All Users:</font></font></span></h3>
<p><font size="2" face="Verdana">These flaws support diverse exploitation methods. Some of the exploits are local, meaning that your perimeter firewall never encounters the attack (unless you use firewalls internally between departments). Installing these updates, therefore, is the most secure course of action.</font></p>
<h3><span><font size="3"><font face="Verdana">Status:</font></font></span></h3>
<p><font size="2" face="Verdana">Apple released updates to fix these issues.</font></p>
<h3><span><font size="3"><font face="Verdana">References:</font></font></span></h3>
<p><span style="font-size:9pt;color:black;font-family:'Verdana','sans-serif';"><a href="http://docs.info.apple.com/article.html?artnum=307562"><font color="#990000">Apple's March OS X Advisory</font></a></span></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Thirteen Security Flaws Plague Safari 3 for OS X and Windows]]></title>
<link>http://bardissi.wordpress.com/?p=367</link>
<pubDate>Wed, 19 Mar 2008 01:07:14 +0000</pubDate>
<dc:creator>bardissi</dc:creator>
<guid>http://bardissi.wordpress.com/?p=367</guid>
<description><![CDATA[Severity: Medium 
18 March, 2008
Summary:

These vulnerabilities affect: Safari 3 for OS X and Windo]]></description>
<content:encoded><![CDATA[<h3><span><font size="3"><font face="Verdana">Severity: Medium </font></font></span></h3>
<p><font size="2" face="Verdana">18 March, 2008</font></p>
<h3><span><font size="3"><font face="Verdana">Summary:</font></font></span></h3>
<ul type="square">
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">These vulnerabilities affect:</span></strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';"> Safari 3 for OS X and Windows </span></li>
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">How an attacker exploits them:</span></strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';"> By enticing one of your users into visiting a malicious web site </span></li>
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">Impact:</span></strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';"> Various results; in the worst case, attacker executes code on your user's computer, with your user's privileges </span></li>
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">What to do:</span></strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';"> Install Safari 3.1 </span></li>
</ul>
<h3><span><font size="3"><font face="Verdana">Exposure:</font></font></span></h3>
<p><font size="2" face="Verdana">Today, Apple released a </font><a href="http://docs.info.apple.com/article.html?artnum=307563"><font size="2" color="#990000" face="Verdana">security update</font></a><font size="2" face="Verdana"> fixing thirteen security issues in Safari 3 for OS X and Windows. The worst of these vulnerabilities potentially allows attackers to execute malicious code on your Safari user's machines. If you use Safari in your network -- whether on a PC or Mac -- you should update to version 3.1 as soon as you can. Some of the fixed vulnerabilities include:</font></p>
<ul type="square">
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">Webkit buffer overflow vulnerability.</span></strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';"> Webkit, a component that ships with Safari, suffers from a <a href="http://www.watchguard.com/glossary/b.asp#buffer_overflow"><font color="#990000">buffer overflow vulnerability</font></a> involving the way it handles <a href="http://www.webopedia.com/TERM/J/JavaScript.html"><font color="#990000">JavaScript</font></a> <a href="http://en.wikipedia.org/wiki/Regular_expressions"><font color="#990000">regular expressions</font></a>. If an attacker can entice one of your users into visiting a malicious web site, he could exploit this vulnerability to execute code on the user's computer, with that user's privileges. </span></li>
</ul>
<ul type="square">
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">Safari certificate spoofing vulnerability.</span></strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';"> According to Apple, Safari suffers from an unspecified SSL <a href="http://www.watchguard.com/glossary/c.asp#certificate"><font color="#990000">certificate</font></a> validation vulnerability. To exploit this vulnerability, an attacker must first entice your user to a legitimate web site that has a legitimate SSL certificate, then re-direct your user to a malicious web site. The malicious web site will appear to have the same SSL certificate as the legitimate site, and thus inherit the trust you give the legitimate site. An attacker could exploit this flaw to steal your login credentials or any other information associated with the legitimate site. </span></li>
</ul>
<ul type="square">
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">Multiple XSS vulnerabilities in Safari.</span></strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';"> Safari and some of its components (WebCore and WebKit) suffer from nine <a href="http://www.watchguard.com/glossary/c.asp#XSS"><font color="#990000">Cross-Site Scripting (XSS) vulnerabilities</font></a>. Though the vulnerabilities differ technically, an attacker could exploit them in the same way, and with similar results. If an attacker can entice one of your users into clicking a malicious link, he can exploit these flaws to execute scripts on that user's computer with that user's privileges. These scripts could do anything from reading the user's cookies to gaining complete control of his PC. For a more general understanding of XSS attacks, see our article, <a href="http://www.watchguard.com/archive/showhtml.asp?pack=135142"><font color="#990000">"Anatomy of a Cross-Site Scripting Attack."</font></a> </span></li>
</ul>
<p><font size="2" face="Verdana">Apple's alert includes a few more flaws, including a web site spoofing vulnerability and password disclosure flaw. For more details on these flaws, refer to </font><a href="http://docs.info.apple.com/article.html?artnum=307430"><font size="2" color="#990000" face="Verdana">Apple's alert</font></a><font size="2" face="Verdana">.</font></p>
<h3><span><font size="3"><font face="Verdana">Solution Path:</font></font></span></h3>
<p><font size="2" face="Verdana">Apple has released Safari 3.1 for OS X and Windows to correct these security vulnerabilities. Safari users should </font><a href="http://www.apple.com/safari/download/"><font size="2" color="#990000" face="Verdana">download and install version 3.1</font></a><font size="2" face="Verdana"> as soon as possible.</font></p>
<p><em><font size="2" face="Verdana">Note: You can also use Apple and OS X's Software Update utility to install the Safari 3.1 update for you automatically.</font></em></p>
<h3><span><font size="3"><font face="Verdana">For All Users:</font></font></span></h3>
<p><font size="2" face="Verdana">These attacks travel as normal-looking HTTP traffic, which you must allow if your network users need to access the World Wide Web. Therefore, the patches above are your best solution.</font></p>
<h3><span><font size="3"><font face="Verdana">Status:</font></font></span></h3>
<p><font size="2" face="Verdana">Apple released Safari 3.1 to fix these flaws.</font></p>
<h3><span><font size="3"><font face="Verdana">References:</font></font></span></h3>
<ul type="square">
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://docs.info.apple.com/article.html?artnum=307563"><font color="#990000">Apple's Safari 3.1 Advisory</font></a> </span></li>
</ul>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox 3 Embraces Color Management Technology]]></title>
<link>http://epiac1216.wordpress.com/?p=123</link>
<pubDate>Fri, 14 Mar 2008 19:45:38 +0000</pubDate>
<dc:creator>Omar Upegui R.</dc:creator>
<guid>http://epiac1216.wordpress.com/?p=123</guid>
<description><![CDATA[One of the features I&#8217;ve missed in Firefox after I found out that such a thing as &#8220;color]]></description>
<content:encoded><![CDATA[<p align="justify"><img src="http://i23.photobucket.com/albums/b389/epiac1216/Mozilla/Firefox.png" align="left" border="1" height="70" width="144" />One of the features I've missed in <b>Firefox</b> after I found out that such a thing as <i>"color management" </i>existed.  This concept came forward when I got acquainted with <b>Apple Safari</b> for Windows.</p>
<p align="justify">Color Management is a standard technique defined by the <a href="http://www.color.org/index.xalter">International Color Consortium</a> to ensure consistent color presentation for images no matter if they are displayed on paper, a computer monitor, an LCD TV set, fabric or any other media.</p>
<p align="justify">While image color improvement will not be as dramatic as I would like, the truth of the matter is, there will certainly be a difference. For example, when you take a picture with your digital camera (specially in RAW format), it not only saves information about the colors, but also the amount of light available, distance and other factors that may affect how an image is perceived. This details are stored in a color profile which as of <i>Firefox 2</i> is just ignored.</p>
<p align="justify"><i>In Firefox 3</i>, these profiles are used to tune up the image to your display to better reproduce the original image; a must for amateur and professional photographers, clothing and fabric related e-stores, paint, food, and mostly everywhere a true representation of color is important.</p>
<p align="justify">Color management is turned off by default to prevent subtle color variations affecting the overall look of web sites. To enable it you must set <i>gfx.color_management.enabled</i> to <i>true</i> (via about:config) and restart <i>Firefox</i>.</p>
<p align="justify">I'm elated that Firefox 3 has added support for <a href="http://en.wikipedia.org/wiki/Color_management">color management</a> technology.  Over the years I've learned to appreciate photography; mainly by reading the blogs of my good friends, <a href="http://brookvilledailyphoto.blogspot.com/">Abraham Lincoln</a> and <a href="http://www.chiriquichatter.net/blog/">Don Ray</a>.   Having color management feature in my web browser will greatly enhance the enjoyment of viewing color photographs.</p>
<p align="justify">I have plans to get my feet wet with color photographs in a couple of months when I buy myself a digital camera.  Right now I'm feeding my piggy bank.  :-)</p>
<p align="justify">Firefox 3 rocks!</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Overhauls Office; Fixes a Dozen Vulnerabilities]]></title>
<link>http://bardissi.wordpress.com/?p=360</link>
<pubDate>Wed, 12 Mar 2008 01:40:31 +0000</pubDate>
<dc:creator>bardissi</dc:creator>
<guid>http://bardissi.wordpress.com/?p=360</guid>
<description><![CDATA[Severity: High
11 March, 2008
Summary:

These vulnerabilities affect: Most current versions of Micro]]></description>
<content:encoded><![CDATA[<h3><font size="3"><font face="Verdana"><span>Severity: </span><font color="#ff0000"><span class="style11"><span>High</span></span><span></span></font></font></font></h3>
<p><font size="2" face="Verdana">11 March, 2008</font></p>
<h3><span><font size="3"><font face="Verdana">Summary:</font></font></span></h3>
<ul>
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">These vulnerabilities affect</span></strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">: Most current versions of Microsoft Office for Windows, and in some cases for Mac (and some other Office-related programs) </span></li>
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">How an attacker exploits them</span></strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">: By enticing you to open maliciously crafted Office documents, visit a malicious web site, or click a malicious link </span></li>
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">Impact</span></strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">: An attacker can execute code, potentially gaining complete control of your computer </span></li>
<li class="MsoNormal"><strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">What to do</span></strong><span style="font-size:9pt;font-family:'Verdana','sans-serif';">: Install the appropriate Office or Office related patches immediately </span></li>
</ul>
<h3><span><font size="3"><font face="Verdana">Exposure:</font></font></span></h3>
<p><font size="2" face="Verdana">Today, Microsoft released four Critical security bulletins describing a dozen vulnerabilities found in components or programs that ship with Microsoft Office for Windows, and in some cases Office for Mac. One of the vulnerabilities also affects Microsoft Visual Studio .NET, Biztalk Server, Commerce Server, and Internet Security and Acceleration Sever. Each vulnerability affects different versions of Office to a different extent.</font></p>
<p><font size="2" face="Verdana">The dozen flaws affect different components and applications within Office, but the end result is always the same. Either by enticing one of your users to download and view a specially crafted Office document, or by luring one of your users to a malicious web page, an attacker can exploit any of these vulnerabilities to execute code on the victim's computer, usually inheriting that user's level of privileges and permissions. If your user has local administrative privileges, the attacker gains full control of the victim's machine.</font></p>
<p><font size="2" face="Verdana">An attacker can exploit many of these flaws using just about any kind of Office document. While two of Microsoft's bulletins specifically mention Excel (.xls) files, one bulletin simply mentions "Office files," which could refer to any Office document type, including Word (.doc), PowerPoint (.ppt), and Publisher (.pub) documents. So, beware of all unexpected Office documents.</font></p>
<p><font size="2" face="Verdana">If you'd like to learn more about each individual flaw, drill into the "Vulnerability Details" section of the security bulletins listed below:</font></p>
<ul>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/3xbjmx"><strong><span style="font-family:'Verdana','sans-serif';"><font color="#990000">MS08-014</font></span></strong></a>:<strong><span style="font-family:'Verdana','sans-serif';"> Multiple Excel vulnerabilities. </span></strong>This bulletin describes seven vulnerabilities involving how Excel handles maliciously crafted Excel documents. By tricking one of your users into downloading and opening an Excel document, an attacker could exploit this flaw to execute code, potentially gaining complete control of that user's computer. </span></li>
</ul>
<ul>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/2ldmq3"><strong><span style="font-family:'Verdana','sans-serif';"><font color="#990000">MS08-015</font></span></strong></a>:<strong><span style="font-family:'Verdana','sans-serif';"> Outlook mailto: URI handling vulnerability.</span></strong> Outlook doesn't properly handle specially crafted <a href="http://shadow2531.com/opera/testcases/mailto/modern_mailto_uri_scheme.html"><font color="#990000">mailto:</font></a> <a href="http://www.webopedia.com/TERM/U/URI.html"><font color="#990000">URI</font></a>s. If an attacker can entice one of your users to click a malicious mailto: link, typically found on a web site, he can exploit this vulnerability to execute code on that user's computer, potentially gaining total control over it. </span></li>
</ul>
<ul>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/3c9ghu"><strong><span style="font-family:'Verdana','sans-serif';"><font color="#990000">MS08-016</font></span></strong></a>: <strong><span style="font-family:'Verdana','sans-serif';">Two Office remote code execution vulnerabilities.</span></strong> This bulletin describes two vulnerabilities involving how Office handles various maliciously crafted Office documents. By tricking one of your users into downloading and opening an Office document, an attacker could exploit this flaw to execute code, potentially gaining complete control of that user's computer. </span></li>
</ul>
<ul>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/35zxja"><strong><span style="font-family:'Verdana','sans-serif';"><font color="#990000">MS08-017</font></span></strong></a>: <strong><span style="font-family:'Verdana','sans-serif';">Two Office Web Component vulnerabilities.</span></strong> Office Web Components allow you to either publish Office spreadsheets, charts, and databases to your web site, or to view such Office content on a web site. The Web Components suffer from two memory corruption vulnerabilities. By enticing one of your users to a malicious web site, an attacker could exploit either vulnerability to execute code on that user's machine, and possibly gain control of it. </span></li>
</ul>
<p><font size="2" face="Verdana">In January, Microsoft released an </font><a href="http://www.microsoft.com/technet/security/advisory/947563.mspx"><font size="2" color="#990000" face="Verdana">early advisory</font></a><font size="2" face="Verdana"> warning customers of a zero day vulnerability in Microsoft Excel, which attackers are currently exploiting in targeted attacks. Microsoft has confirmed that </font><a href="http://tinyurl.com/3xbjmx"><font size="2" color="#990000" face="Verdana">MS08-014</font></a><font size="2" face="Verdana"> fixes this outstanding Excel vulnerability. Since Microsoft rates all of these bulletins as Critical, and one bulletin fixes a flaw that attackers are currently exploiting in the wild, we consider these flaws a serious risk. You should patch them immediately.</font></p>
<h3><span><font size="3"><font face="Verdana">Solution Path</font></font></span></h3>
<p><font size="2" face="Verdana">Microsoft has released patches for Office (and a few related programs) to correct all of these vulnerabilities. You should download, test, and deploy the appropriate patches throughout your network immediately.</font></p>
<p><a href="http://tinyurl.com/3xbjmx"><font size="2" color="#990000" face="Verdana">MS08-014</font></a><strong><span style="font-family:'Verdana','sans-serif';"><font size="2">:</font></span></strong></p>
<p><strong><span style="font-family:'Verdana','sans-serif';"><font size="2">Excel update for: </font></span></strong></p>
<ul>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/282mg5"><font color="#990000">Office 2000 w/SP3</font></a> (KB946979) </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/yqjtby"><font color="#990000">Office XP w/SP3</font></a> (KB946976) </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/yuj69m"><font color="#990000">Office 2003 w/SP2</font></a> (KB943985) </span>
<ul>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/yopndy"><font color="#990000">Excel Viewer 2003</font></a> (KB943889) </span></li>
</ul>
</li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/258ma8"><font color="#990000">2007 Microsoft Office System</font></a> (KB946974) </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/2f39bf"><font color="#990000">Office 2004 for Mac</font></a> (KB949357) </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/257jj3"><font color="#990000">Office 2008 for Mac</font></a> (KB948057) </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/2cndzj"><font color="#990000">Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats</font></a> (KB947801) </span></li>
</ul>
<p><a href="http://tinyurl.com/2ldmq3"><font size="2" color="#990000" face="Verdana">MS08-015</font></a><strong><span style="font-family:'Verdana','sans-serif';"><font size="2">:</font></span></strong></p>
<p><strong><span style="font-family:'Verdana','sans-serif';"><font size="2">Outlook update for: </font></span></strong></p>
<ul>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/yryxo2"><font color="#990000">Office 2000 w/SP3</font></a> (KB946986) </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/ysvsxv"><font color="#990000">Office XP w/SP3</font></a> (KB946985) </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/25878p"><font color="#990000">Office 2003</font></a> (KB945432) </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/yrsce5"><font color="#990000">2007 Microsoft Office System</font></a> (KB946983) </span></li>
</ul>
<p><a href="http://tinyurl.com/3c9ghu"><font size="2" color="#990000" face="Verdana">MS08-016</font></a><font size="2" face="Verdana">: </font></p>
<ul>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/2egmdk"><font color="#990000">Office 2000 w/SP3</font></a> (KB947361) </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/ywu7tk"><font color="#990000">Office XP w/SP3</font></a> (KB947866) </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/2zfwc8"><font color="#990000">Office 2003 w/SP2</font></a> (KB947355) </span>
<ul>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/2zfwc8"><font color="#990000">Excel Viewer 2003</font></a> (KB947355) </span></li>
</ul>
</li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/2f39bf"><font color="#990000">Office 2004 for Mac</font></a> (KB949357) </span></li>
</ul>
<p><a href="http://tinyurl.com/35zxja"><font size="2" color="#990000" face="Verdana">MS08-017</font></a><font size="2" face="Verdana">:</font></p>
<p><strong><span style="font-family:'Verdana','sans-serif';"><font size="2">Office Web Components update for: </font></span></strong></p>
<ul>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/2ndvvj"><font color="#990000">Office 2000 w/SP3</font></a> (KB931660) </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/2l7xpx"><font color="#990000">Office XP w/SP3</font></a> (KB932031) </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/2j7c96"><font color="#990000">Visual Studio .NET 2002</font></a> (KB933367) </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/34q3or"><font color="#990000">Visual Studio .NET 2003</font></a> (KB933369) </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/363t2c"><font color="#990000">Biztalk Server 2000</font></a> (KB939714) </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/2zv8cg"><font color="#990000">Biztalk Server 2002</font></a> (KB939714) </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/2ut58d"><font color="#990000">Commerce Server 2000</font></a> (KB941305) </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';"><a href="http://tinyurl.com/2njegd"><font color="#990000">Internet Security and Acceleration Server 2000</font></a> (KB948257) </span></li>
</ul>
<h3><span><font size="3"><font face="Verdana">For All WatchGuard Users:</font></font></span></h3>
<p><font size="2" face="Verdana">Attackers exploit some of these vulnerabilities by enticing your users into downloading and viewing various Office documents. You can configure some of WatchGuard's Firebox models to block all Office documents. However, most organizations need to allow Office documents in order to conduct business, and blocking them could bring your business to a halt. Furthermore, the remaining attacks travel as normal-looking HTTP traffic, which you must allow if your network users need to access the World Wide Web. Therefore, the patches above are your best solution.</font></p>
<h4><span><font face="Verdana">Status:</font></span></h4>
<p><font size="2" face="Verdana">Microsoft has released patches correcting these issues.</font></p>
<h3><span><font size="3"><font face="Verdana">References:</font></font></span></h3>
<ul>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';">Microsoft Security Bulletin <a href="http://tinyurl.com/3xbjmx"><font color="#990000">MS08-014</font></a> </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';">Microsoft Security Bulletin <a href="http://tinyurl.com/2ldmq3"><font color="#990000">MS08-015</font></a> </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';">Microsoft Security Bulletin <a href="http://tinyurl.com/3c9ghu"><font color="#990000">MS08-016</font></a> </span></li>
<li class="MsoNormal"><span style="font-size:9pt;font-family:'Verdana','sans-serif';">Microsoft Security Bulletin <a href="http://tinyurl.com/35zxja"><font color="#990000">MS08-017</font></a> </span></li>
</ul>
]]></content:encoded>
</item>
<item>
<title><![CDATA[PayPal: Apple's Safari Sucks]]></title>
<link>http://techbitch.net/2008/03/03/paypal-apples-safari-sucks/</link>
<pubDate>Mon, 03 Mar 2008 08:46:15 +0000</pubDate>
<dc:creator>chopperarris</dc:creator>
<guid>http://techbitch.net/2008/03/03/paypal-apples-safari-sucks/</guid>
<description><![CDATA[PayPal said you should drop Apple’s Safari browser if you want to avoid online fraud.Safari doesn]]></description>
<content:encoded><![CDATA[<p>PayPal said you should drop Apple’s Safari browser if you want to avoid online fraud.Safari doesn’t make PayPal’s list of recommended browsers because it doesn’t have two important anti-phishing security features, according to PayPal.</p>
<p>Apparently, Apple is lagging behind what they need to do to protect their customers. PayPal recommends at this point to use Internet Explorer 7 or 8 when it comes out, or Firefox 2 or Firefox 3, or indeed Opera. Basically, anything but Safari.</p>
<p>Safari is the default browser on Apple’s Macintosh computers and the iPhone, but it is also available for the PC. Both Firefox and Opera run on the Mac.</p>
<p>Unlike its competitors, Safari has no built-in phishing filter to warn users when they are visiting suspicious Web sites. Another problem is Safari’s lack of support for another anti-phishing technology, called Extended Validation (EV) certificates. This is a secure Web browsing technology that turns the address bar green when the browser is visiting a legitimate Web site.</p>
<p>When it comes to fighting phishing Safari has got nothing in terms of security support, only SSL (Secure Sockets Layer encryption) - that’s it! An emerging technology, EV certificates are already supported in Internet Explorer 7, and they’ve been used on PayPal’s Web site for more than a year now. When IE 7 visits PayPal, the browser’s address bar turns green - a sign that the site is legitimate. Upcoming versions of Firefox and Opera are expected to support the technology.</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Office Riddled with Security Holes ]]></title>
<link>http://bardissi.wordpress.com/2008/02/12/microsoft-office-riddled-with-security-holes/</link>
<pubDate>Wed, 13 Feb 2008 00:17:17 +0000</pubDate>
<dc:creator>bardissi</dc:creator>
<guid>http://bardissi.wordpress.com/2008/02/12/microsoft-office-riddled-with-security-holes/</guid>
<description><![CDATA[Severity: High 
12 February, 2008
Summary:

These vulnerabilities affect: Many current versions of M]]></description>
<content:encoded><![CDATA[<h3><font face="Verdana"><span>Severity: </span><span class="style11"><span><font color="#ff0000">High</font></span></span><span> </span></font></h3>
<p><font size="2" face="Verdana">12 February, 2008</font></p>
<h3><span><font face="Verdana">Summary:</font></span></h3>
<ul>
<li class="MsoNormal"><strong><span style="font-size:10pt;font-family:'Verdana','sans-serif';">These vulnerabilities affect</span></strong><span style="font-size:10pt;font-family:'Verdana','sans-serif';">: Many current versions of Microsoft Office for Windows (MS08-013 affects OS X, too) and Microsoft Works and Works Suite </span></li>
<li class="MsoNormal"><strong><span style="font-size:10pt;font-family:'Verdana','sans-serif';">How an attacker exploits them</span></strong><span style="font-size:10pt;font-family:'Verdana','sans-serif';">: By enticing you to open maliciously crafted Office documents </span></li>
<li class="MsoNormal"><strong><span style="font-size:10pt;font-family:'Verdana','sans-serif';">Impact</span></strong><span style="font-size:10pt;font-family:'Verdana','sans-serif';">: An attacker can execute code, potentially gaining complete control of your computer </span></li>
<li class="MsoNormal"><strong><span style="font-size:10pt;font-family:'Verdana','sans-serif';">What to do</span></strong><span style="font-size:10pt;font-family:'Verdana','sans-serif';">: Install the appropriate Office or Works patches immediately. </span></li>
</ul>
<h3><span><font face="Verdana">Exposure:</font></span></h3>
<p><font size="2" face="Verdana">Today, Microsoft released four security bulletins describing seven vulnerabilities found in components or pro