Apple Safari Update Patches 16 Vulnerabilities Ahead of Hacking Contest | eWeek

Apple Safari Update Patches 16 Vulnerabilities Ahead of Hacking Contest

Écrit par
Brian Prince
Brian Prince
Mar 12, 2010
1 minute read
eWeek Le contenu et les recommandations de produits sont indépendants de la rédaction. Nous pouvons gagner de l'argent lorsque vous cliquez sur des liens vers nos partenaires. En savoir plus

Apple issued patches for 16 vulnerabilities in Safari, including 12 bugs that could be used to execute code on a vulnerable machine and potentially take full control.

According to Apple’s advisory, nine of the 16 flaws rested in Webkit, Safari’s open-source browser engine, and all but one of those can be exploited to execute arbitrary code on a victim’s machine. Of the nine, seven deal with what Apple called “use-after-free” issues tied to Webkit’s handling of incorrectly nested HTML tags, its parsing of XML documents and its handling of HTML elements and callbacks for those elements.

Four of the patches fix issues in the ImageIO component. The most serious of these are memory corruption and buffer overflow vulnerabilities attackers could exploit with malicious TIFF images to compromise users and execute arbitrary code. Both the other ImageIO patches deal with uninitialized memory access issues tied to the component’s handling of BMP and TIFF images, respectively.

Apple also fixed a heap buffer overflow vulnerability in the ColorSync component, a cookie handling issue in PubSub and a problem with Safari’s handling of external URL schemes.

The fixes come roughly two weeks ahead of Pwn2Own 2010 hacking challenge, where researchers will take a shot and bringing down the security of Safari, Microsoft Internet Explorer, Mozilla Firefox and Google Chrome in a battle for $40,000 in prize money. The contest, which also includes a smartphone challenge for $60,000, will be held March 24-26 at the CanSecWest security conference in Vancouver, B.C.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Propriété de TechnologyAdvice. © 2026 TechnologyAdvice. Tous droits réservés

Divulgation publicitaire : Certains des produits qui apparaissent sur ce site proviennent d'entreprises dont TechnologyAdvice reçoit une compensation. Cette compensation peut influencer la façon dont les produits apparaissent sur ce site, notamment l'ordre dans lequel ils apparaissent. TechnologyAdvice n'inclut pas toutes les entreprises ou tous les types de produits disponibles sur le marché.