GBK.Xscape Posted August 1, 2007 Share Posted August 1, 2007 The first update to the iPhone Description: Safari's security model prevents JavaScript in remote web pages from modifying pages outside of their domain. A race condition in page updating combined with HTTP redirection may allow JavaScript from one page to modify a redirected page. This could allow cookies and pages to be read or arbitrarily modified. This update addresses the issue by correcting access control to window properties. Credit to Lawrence Lai, Stan Switzer, and Ed Rowe of Adobe Systems, Inc. for reporting this issue. Description: Heap buffer overflows exist in the Perl Compatible Regular Expressions (PCRE) library used by the JavaScript engine in Safari. By enticing a user to visit a maliciously crafted web page, an attacker may trigger the issue, which may lead to arbitrary code execution. This update addresses the issue by performing additional validation of JavaScript regular expressions. Credit to Charlie Miller and Jake Honoroff of Independent Security Evaluators for reporting these issues. Description: An HTTP injection issue exists in XMLHttpRequest when serializing headers into an HTTP request. By enticing a user to visit a maliciously crafted web page, an attacker could trigger a cross-site scripting issue. This update addresses the issue by performing additional validation of header parameters. Credit to Richard Moore of Westpoint Ltd. for reporting this issue. Just a few of the things fixed in the update... a complete list can be found here - Update List Link to comment https://www.insanelymac.com/forum/topic/58660-iphone-update-101-now-available/ Share on other sites More sharing options...
TvvqKMZ72bsklauw5 Posted August 1, 2007 Share Posted August 1, 2007 Woohoo! Now for the software update that allows use of the hidden 3G hardware...whoops...that slipped out, ignore that last statement. Link to comment https://www.insanelymac.com/forum/topic/58660-iphone-update-101-now-available/#findComment-418745 Share on other sites More sharing options...
Recommended Posts