Forbidden Web

Jun 20, 2008 Apple Releases Safari v3.1.2 for Windows
Apple has released Safari v3.1.2 for Windows to address multiple vulnerabilities. These vulnerabilities include the following:
  • an out-of-bounds memory read when handling BMP and GIF files that may lead to the disclosure of memory contents
  • an issue in the way Windows desktop handles executables, which may allow arbitrary code execution
  • an issue in the way Safari handles executables from websites in a trusted Internet Explorer zone, which may lead to automatic arbitrary code execution
  • a memory corruption issue in the handling of JavaScript arrays by WebKit that may lead to an unexpected application termination or arbitrary code execution
US-CERT encourages users to review Apple Article HT2092 and upgrade to Safari v3.1.2 for Windows.