Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Researchers: Apple to patch Safari before Pwn2Own
MacWorld ^ | Mar 4, 2011 5:05 AM | by Gregg Keizer

Posted on 03/04/2011 10:51:35 PM PST by Swordmaker

Apple will patch its Safari browser before the Pwn2Own hacking contest kicks off next week, security researchers hinted Thursday.

If accurate, Apple will join both Google and Mozilla, which earlier this week issued security updates for Chrome and Firefox as preparation for Pwn2Own.

On Wednesday, Apple patched a record 57 vulnerabilities in its iTunes music software; 50 of those bugs were attributed to WebKit, the open-source browser engine that Safari’s built on. iTunes relies on WebKit to render its online store component.

“Anti-pwn2own again: Apple fixed a record of 50 vuln[erabilities] in WebKit (iTunes), and is preparing the update for Safari/Mac OS X,” said French security firm Vupen in a message on its Twitter account.

Vupen’s mention of Pwn2Own refers to the annual hacking contest held at the CanSecWest security conference in Vancouver, British Columbia. This year's Pwn2Own runs March 9-11.

At Pwn2Own, security researchers will compete for $65,000 in prizes by trying to take down the most up-to-date editions of Safari 5, Google's Chrome 9, Microsoft's Internet Explorer 8 and Mozilla's Firefox 3.6.

It’s not unusual for Apple to patch WebKit flaws in one application before it rolls out those same fixes for another. In the past, however, it’s usually patched WebKit vulnerabilities in Safari before addressing them in iTunes.

Other clues to an upcoming Safari update came from HP TippingPoint—coincidentally the sponsor of Pwn2Own—which issued advisories on two WebKit bugs patched in iTunes Wednesday. The bugs were originally reported to TippingPoint’s Zero Day Initiative (ZDI) bug bounty program; ZDI passed the reports to Apple last October.

Both the advisories said that attackers could exploit the bugs to “execute arbitrary code on vulnerable installations of Apple ... WebKit” and that the vulnerabilities could be triggered using “drive-by” tactics that only require a victim to visit a malicious Web site.

Another hint that Safari will be patched soon came from the iTunes advisory posted by Apple on Wednesday. None of the 50 WebKit bugs listed in the advisory were accompanied by the usual terse Apple description; instead, Apple only noted the CVE (Common Vulnerabilities and Exposures) identifying number and the researcher(s) who first reported the flaw.

More than 30 of the 50 WebKit vulnerabilities were credited to Google researchers and developers. Google’s Chrome, like Safari, is built on the WebKit engine.

If Apple patches Safari, it will be the third browser to update this week.

Google patched 19 bugs in Chrome on Monday, and Mozilla followed that on Tuesday with an 11-patch update to Firefox .

Last year, only Apple and Google updated their browsers just before Pwn2Own. Mozilla acknowledged a critical vulnerability in Firefox less than a week before 2010’s contest, but said it wouldn’t fix the flaw in time for the challenge. Pwn2Own organizers later ruled that Firefox vulnerability off limit.

Assuming Apple updates Safari, of the four Pwn2Own-targeted browsers, only Internet Explorer (IE) will remain unpatched in the days leading up to the contest. Microsoft last issued fixes for IE flaws on Feb. 8 as part of its monthly Patch Tuesday.


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: apple; patch; update
Navigation: use the links below to view more comments.
first previous 1-2021-32 last
To: allmost
Your really milking this.

Try this: You're really milking this. If you're going to be a disrupter at least do it correctly.

21 posted on 03/05/2011 7:13:56 AM PST by Mind-numbed Robot (Not all that needs to be done needs to be done by the government!)
[ Post Reply | Private Reply | To 2 | View Replies]

To: WVKayaker

KNOCK IT OFF!! AND I MEAN YOU!!


22 posted on 03/05/2011 8:43:48 AM PST by Admin Moderator
[ Post Reply | Private Reply | View Replies]

To: Admin Moderator; Swordmaker
Whatever. Your bold letters make me wonder whose side is being jerked. I complained about a troll and get tromped on.

I guess trolls are permissible now. Sorry if I brought disservice, but disruption for the sake of personal jollies was stated as being a wrong-headed POV. I was pointing it out, and most of my posts have been removed, but the troll stands proud and gloating. The deliberate use of demeaning words and ad hominems is a little hard to handle.

What am I getting wrong? He is a troll.

23 posted on 03/05/2011 10:00:00 AM PST by WVKayaker ("When Sarah Palin speaks, people listen!" - EF Hutton)
[ Post Reply | Private Reply | To 22 | View Replies]

To: allmost
> Used to be free BSD, Apple stole it.

Sorry, you're ignorant of the facts. Apple didn't steal anything, FreeBSD is free, and OS-X came from NextStep and Mach. Read a little history of the thing before you accuse people of stealing.

If you're going to to troll, at least get your facts straight. Sheesh.

24 posted on 03/05/2011 10:51:13 AM PST by dayglored (Listen, strange women lying in ponds distributing swords is no basis for a system of government!)
[ Post Reply | Private Reply | To 16 | View Replies]

To: WVKayaker; Swordmaker
> I guess trolls are permissible now.

Heck, they're getting supported, and my light-hearted response (#13) gets pulled, wtfo. Time to sit back and let the tech threads degenerate again. I don't have the energy today to play footsie with this cr@p.

25 posted on 03/05/2011 10:51:40 AM PST by dayglored (Listen, strange women lying in ponds distributing swords is no basis for a system of government!)
[ Post Reply | Private Reply | To 23 | View Replies]

To: dayglored; All
>> > I guess trolls are permissible now.

> Heck, they're getting supported, and my light-hearted response (#13) gets pulled, wtfo. Time to sit back and let the tech threads degenerate again. I don't have the energy today to play footsie with this cr@p.

Sorry, I guess that was a little nasty. I'm just very frustrated. JimRob made his position -- and thus the site policy -- very clear, and while he's dealing with much more serious problems (his leg), some people take advantage to push their own agenda. Seems disrespectful, to me.

Prayers up again, for Jim's rapid recovery and return.

26 posted on 03/05/2011 11:10:10 AM PST by dayglored (Listen, strange women lying in ponds distributing swords is no basis for a system of government!)
[ Post Reply | Private Reply | To 25 | View Replies]

To: WVKayaker
Your bold letters make me wonder...What am I getting wrong?

THIS IS BOLD.
THIS IS CAPITALIZED.

27 posted on 03/05/2011 8:20:46 PM PST by Admin Moderator
[ Post Reply | Private Reply | To 23 | View Replies]

To: allmost
Used to be free BSD, Apple stole it. Now it’s a Mac. Is that better? :)

That is FALSE... Apple OSX Is fully licensed and is a registered and trademarked, fully certified version of UNIX. no theft was involved. To claim that is a lie. It is one of only four so certified by the UNIX organization to use the UNIX trademarks.

28 posted on 03/05/2011 8:35:07 PM PST by Swordmaker (This tag line is a Microsoft product "insult" free zone.)
[ Post Reply | Private Reply | To 16 | View Replies]

To: Swordmaker

Well said.


29 posted on 03/06/2011 7:51:50 PM PST by SunkenCiv (The 2nd Amendment follows right behind the 1st because some people are hard of hearing.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Swordmaker

Touchy with the rubs. Pretend BSD base isn’t stolen from the freeware developers and warped into an Apple OS.


30 posted on 03/08/2011 8:00:09 PM PST by allmost
[ Post Reply | Private Reply | To 28 | View Replies]

To: allmost; antiRepublicrat; dayglored
Touchy with the rubs. Pretend BSD base isn’t stolen from the freeware developers and warped into an Apple OS.

I don't have to pretend anything, almost. I know the facts.

You are an idiot if you think that the fully licensed, and registered version of FreeBSD UNIX that is at the core of OSX is stolen. Do you REALLY think that the organization that licenses UNIX would grant Apple has made a lot of developments and advancements in FreeBSD and put it back out into the FOS software environment. Apple outright owns the rights to CUPS, WEBKIT, and quite a few other components of UNIX, and has licensed them back to others to use in the open software community including the LINUX variants. Even Android uses a lot of Apple's open source software that's been licensed openly like WEBKIT.

31 posted on 03/09/2011 1:44:48 AM PST by Swordmaker (This tag line is a Microsoft product "insult" free zone.)
[ Post Reply | Private Reply | To 30 | View Replies]

To: Swordmaker
I am an idiot in many ways. I don't dislike Apple. The ‘cult’ of Apple is disturbing. Huffington followed a similar approach recently IMO.
32 posted on 03/09/2011 2:58:27 PM PST by allmost
[ Post Reply | Private Reply | To 31 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-32 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson