Network Computing is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them. Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Apple Patches Three Bugs In Safari For Windows Beta: Page 2 of 3

Since this is a beta release, Ullrich said he expects to see fairly frequent updates coming out.

According to an Apple advisory issued Thursday, a command injection vulnerability in the original beta could be used to trigger remote code execution. The bug could be exploited if the user visits a malicious Web site. This update fixes the vulnerability by performing additional processing and URL validation, according to the advisory.

The two other bugs being fixed in this beta version also can be exploited if a user visits a malicious Web site.

One bug could allow cross-site scripting. The flaw enables a hacker to gain access to JavaScript objects or to remotely execute JavaScript in the context of another Web page. This flaw does not affect Mac OS X systems.

Apple describes the last bug being patched as an out-of-bounds memory read issue, which could lead to unexpected application termination or arbitrary code execution when a user visits a malicious Web site. This, too, does not affect Mac OS X systems.