MacDailyNews - Where Mac news comes first

Apple Store

5 Day Most Commented

Opinion Archive

Current Headlines

Latest Joy of Tech

  • Latest Joy of Tech!

MacNN

AppleInsider

MacMinute

Macworld UK

Yahoo! Finance AAPL

iTunes Top 10 Albums

Mac OS X Downloads

Thu, May 22, 2008 - 03:50 PM EDT  —  AAPL: 174.92 (-3.27, -1.84%) |  NASDAQ: $data[1] ($data[4], $percent)"; //close the filehandle $fp fclose ($fp); ?>

Apple releases Safari 3.0.1 Public Beta for Windows with numerous security improvements
Thursday, June 14, 2007 - 09:38 AM EDT

Apple has released Safari 3.0.1 Public Beta for Windows XP and Vista which includes numerous security improvements which Apple notes do not affect Safari 3 Public Beta for Mac OS X.

Safari 3.0.1 Public Beta for Windows addresses the following issues in Safari 3 Public Beta for Windows:

CVE-ID: CVE-2007-3186
Impact: Visiting a malicious website may lead to arbitrary code execution.
Description: A command injection vulnerability exists in the Windows version of Safari 3 Public Beta. By enticing a user to visit a maliciously crafted web page, an attacker can trigger the issue which may lead to arbitrary code execution. This update addresses the issue by performing additional processing and validation of URLs. This does not pose a security issue on Mac OS X systems, but could lead to an unexpected termination of the Safari browser.

CVE-ID: CVE-2007-3185
Impact: Visiting a malicious website may lead to an unexpected application termination or arbitrary code execution.
Description: An out-of-bounds memory read issue in Safari 3 Public Beta for Windows may lead to an unexpected application termination or arbitrary code execution when visiting a malicious website. This issue does not affect Mac OS X systems.

CVE-ID: CVE-2007-2391
Impact: Visiting a malicious website may allow cross-site scripting.
Description: A race condition in Safari 3 Public Beta for Windows may allow cross site scripting. Visiting a maliciously crafted web page may allow access to JavaScript objects or the execution of arbitrary JavaScript in the context of another web page. This issue does not affect Mac OS X systems.

The update is available via the "Apple Software Update" application, which is installed with the most recent version of QuickTime or iTunes on Windows.

MacDailyNews Take: That was about as fast as, oh, say, putting a cigarette out in someone's eye and certainly more productive.

  • Social Web
  • E-mail






Always -- Free ground shipping with orders over $50 at the Apple Store.

Reader Feedback: ( = registered)

Jun 14, 07 - 09:39 am Comment from: R

Wow, that was quick.

Jun 14, 07 - 09:45 am Comment from: mark

Hey, hey, now the silly un-informed conspiracy folks can come out and say that Apple release Safari 3 on purpose to show that the Mac OS is more secure than Windows.
smile

Jun 14, 07 - 09:46 am Comment from: ron

Stupid move. Apple should have done more testing. Now thousands of Windows users are pissing and moaning about how lousy Safari is, after using it before this release. I know, I know, it's a beta release. Tell that to the media.

Jun 14, 07 - 09:47 am Comment from: MattyG

see! it's what beta is all about

and perhaps a sneaky ploy to gain more publicity

Jun 14, 07 - 09:52 am Comment from: M.T. Wence

so, the media says... "Safari Beta is buggy!" to which most people reply "yeah, it's a beta".

i think stupidity is overblown.

Jun 14, 07 - 09:56 am Comment from: Kazmania

Ok, to ANYONE who is bashing Apple for releasing an application with "bugs" or "security issues", etc. - SHUT THE PIE HOLE! Do you know the meaning of the word BETA???? One of the purposes of releasing a program in beta to the public is TO FIND ADDITIONAL PROBLEMS - IE BUGS AND SECURITY PROBLEMS, only then can the company (Apple) make the necessary changes! Apple does not have the experience in releasing Windows apps like many other companies, and therefore, this is probably the best way for their staff to find the remaining problems and get them corrected before releasing a GM of the app. Good God people, you think a beta application shouldn't have any problems to it!

Jun 14, 07 - 09:56 am Comment from: iprodreviews.blogspot.com

But in tests by Wired News Safari was slower than both Internet Explorer 7 and Firefox 2

Check out the story & the test results at

http://iprodreviews.blogspot.com/2007/06/safari-3-is-slower-than-ie-7-firefox.html

Jun 14, 07 - 09:57 am Comment from: Cubert

"Mac OS X is unaffected."

As usual. Nothing to see here.

Jun 14, 07 - 10:04 am Comment from: MCCFR

Can I say Safari 3 works perfectly on my system, but then I was smart enough to buy a Macintosh.

And - to those Windows users who are whinging – a) remember what the Vista beta was like and b) it's a fscking beta. Microsoft were responsible for the rise in popularity of public beta programmes back when they pre-launched Win95 (a whole operating system - although that's using the term loosely) and got a couple of million people to help them debug it - don't whine if Apple now uses the same approach for a browser.

Jun 14, 07 - 10:10 am Comment from: MacMan

@iprodreviews

In response to this, Apple tested the speed of Safari independent of the internet, in otherwords raw compiling and load speeds. You can't perform a speed test using live data from the internet because there are too many variables. You are relying on the speed of the servers from the hosted site, you are relying on the packet data delivery, and you are relying on your connection as well.

Speed has to be determined with all of those variables removed, otherwise the test is useless. Apple understood this and that is how they tested Safari's speed.

Jun 14, 07 - 10:13 am Comment from: RC

Let's see M$ or even Firefox fix vulnerabilities in less than 3 days! They never get security updates out even close to this fast. Anyone that is bitching about this Safari beta for Windows is nothing more than a M$ fanboi anyway...

Jun 14, 07 - 10:17 am Comment from: Quevar

@ iprodreviews.blogspot.com:

The tester used a website that Safari is known to have issues with. Even if that wasn't the case, they only used one website to test, which is statistically worthless, unless you only use one website. The tester really should test it on several websites using different technologies (such as JavaScript, CSS, AJAX, larged nested tables, etc.) and see who comes out ahead on all of them.

Jun 14, 07 - 10:17 am Comment from: Buster

The turnaround speed was interesting. What this means is a TON of advertizing for Apple. Even if bad, everyone was hearing about Safari for Windows. Apple shows that it is lightening quick to fix wrongs showing just how responsive it is to its customers.

All good.......brilliant!

Jun 14, 07 - 10:17 am Comment from: clyde

Funny how Windows folks of all people could scream about a couple of security holes right after a beta was released. I suspect that if this was from Redmond, they'd be lined up to sing Steve Ballmer's praises, and encouraging people to have patience and give this a chance. They're the same people who are willing to wait until MS posts its SP1 patch to Vista before they make a final judgment.

Apple could, and should, have done better in releasing this, though. Apple is the Avis of the pc world, it has to work harder and be better than the market leader. Hopefully this will patch the holes and encourage people to try the browser.

Jun 14, 07 - 10:18 am Comment from: shen

"Now thousands of Windows users are pissing and moaning about how lousy Safari is, after using it before this release. "

aside from 'Mac at home windows at work' and a few really diehard nerds, how many windows users do you really think have even HEARD about it yet? 12? 15?

this won't be anything important to the windows world until it starts getting downloaded by millions of iPhone users in a few weeks. as long as it is ready by then.......

Jun 14, 07 - 10:18 am Comment from: scott

Same application, different platforms. I can't imagine a better comparison of the inherent security of both platforms. Probably a better test than iTunes because the internet is the security metric these days. The development fork didn't hurt iTunes, let's hope it's the same for Safari.

Long live Unix and Apple's ability to let most users not care what it is.

Jun 14, 07 - 10:21 am Comment from: Anonymous Poster

Anyone notice that Safari for Windows does not follow the Windows OS look and feel and guidelines at all? Look at the way notification boxes slide out of the menu bar, the way fonts are rendered, clicking and dragging images from a web page to a desktop, preference panes, etc.... Compare this with iTunes for Windows which does follow the Windows UI more closely, where for example the preferences are divided into tabs (typical Windows style). It's like instead of just porting Safari to Windows, they have created a Mac "layer" on top of Windows. It's weird.

Jun 14, 07 - 10:23 am Comment from: jay

While I see both sides of this argument, Apple almost always has the high ground on quality and stability of its software, particularly compared to M$. Most of the time, if not always, an Apple "beta" exceeds M$'s released software in quality

Apple released a bad, bad first beta, there's no getting around it here. In this one instance, Apple blew it.

Jun 14, 07 - 10:28 am Comment from: Jeff

iTunes keeps crashing since I installed Safari on my Mac.

Jun 14, 07 - 10:38 am Comment from: Pete

You have to wonder if this was intentional... I mean, an update fixing vulnerabilites just 2 days after a software release makes Apple "look good" for being responsive while at the same time it really points out the flaws of the Windows platform... Hmm.

Jun 14, 07 - 10:38 am Comment from: Joe

Considering that this safari product is actually the latest product to be ported from OSX. Chances are, it is using the same framework that Itunes is using, but it is a much more feature filled framework.

Jun 14, 07 - 10:39 am Comment from: bizarro ballmer

I don't know if it's my imagination but Safari3 is pretty snappy on my G4 powerbook.

Jun 14, 07 - 10:44 am Comment from: peach picker

This is another ice cube for the water glass (in hell)

Jun 14, 07 - 10:44 am Comment from: adman

I've been looking for 15 minutes trying to figure out how to do the update. Anyone here know how to do it? Thanks.

Jun 14, 07 - 10:45 am Comment from: Jamie

I would be more shocked if the beta was perfect in every way.

Jun 14, 07 - 10:49 am Comment from: schmluss

It's ironic that the people that Microsoft piad to spread FUD about the Safari for Windows beta, caused Apple to respond so fast to improve their product. Maybe Ballmer will be throwing more chairs today than he did on Monday?

Jun 14, 07 - 10:55 am Comment from: -Diz.

My Apple Software Update says my software is up to date even though I have Safari 3.0 installed. How do I get it to see that I need the 3.0.1 update?

Jun 14, 07 - 11:00 am Comment from: adman

I just found it. Go to Start > Programs > Apple Software Update.

That will update all the Apple software on your machine. Geesh! Windows is so lame.

Jun 14, 07 - 11:01 am Comment from: caddisfly

to Diz

...try "about Safari"

Jun 14, 07 - 11:05 am Comment from: Shinobi

I would prefer for Apple to set a higher standard when delivering software to the Windows world.

But the windoze users are used to Buggy Software....why should they be so upset. The majority of windoze users use IE, which is not even beta software and still is buggy as hell!

I think Apple is learning from this experience and will get better in future releases. I think they are really learning how easy it is for software to be exploited on a windows operating system.

Notice how these vulnerabilities do not affect safari on a Mac!

Jun 14, 07 - 11:07 am Comment from: oh my

@ adman

".....I've been looking for 15 minutes trying to figure out how to do the update. Anyone here know how to do it? Thanks...."
Click Here

Jun 14, 07 - 11:08 am Comment from: Angelus520

Winbloze doesn't see that I need the new Safari update, either. Anyway to force it to update? My "About Safari" shows version 3.0 and I ran the stupid Start>Programs thing.

Jun 14, 07 - 11:10 am Comment from: Ray

Ain't so easy to make secure software for Windoze, huh....

Just my $0.02

Jun 14, 07 - 11:12 am Comment from: hedgehogfrenzy

Too bad they didn't update any bugs yet. I know it's BETA, but it crashes every time I try to login to the Windows server proxy at work, Safari crashes instantly. I'd like to be able to use this software!

Jun 14, 07 - 11:15 am Comment from: -Diz.

caddisfly:

I didn't clarify. I'm at work and running Safari Version 3.0 (522.11.3) on my Windows XP machine. The "About Safari" box doesn't have an update software selection, nor does that option reside anywhere else in Safari 3.0 Beta for Windows. I'm stuck running Apple Software Update (for Windows) and it's not seeing Safari 3.0.1.

:-(

Jun 14, 07 - 11:19 am Comment from: sunnyhours

I just used Apple Software Update here at work (Windows XP PC) - found the update no problem. I am now running 3.0.1.

Jun 14, 07 - 11:22 am Comment from: MacMania

Expect Safari 3.0 to be at 3.0.239 in no time, and remain at 3.0.0 on the Mac.

The whole Windows world does in fact suck.

Rock on Steve!
rasberry

Jun 14, 07 - 11:26 am Comment from: ZDNet Blog Readers are Flacid With Rage!

Most of the blogs on ZDNet since the keynote are about Apple. And they hate us. Getting involved with any of the discussions there is totally frustrating and it's best just to stay away from all that fear and loathing. Especially that "NonZealot" poster. He's totally batshit!

Jun 14, 07 - 11:31 am Comment from: Zorrin

Actually, installing Safari 3 on my Mac screwed up my iChat. I'm not the only one, either, as it seems that lots of people are having the same problem:

http://forums.macrumors.com/showthread.php?t=313002

Jun 14, 07 - 11:48 am Comment from: eWorldian

Since installing Safari 3.0 on my Intel iMac, I can no longer view PDF files in the Safari window.
I have Acrobat Pro 8 and have used the "Repair Acrobat Installation" to reinstall the PDF Viewer for Safari but that doesn't help.

Anybody have any ideas?

Jun 14, 07 - 11:49 am Comment from: Angelus520

Seems pretty dumb but I just went ahead and downloaded the whole thing from Apple again. Now my Winbloze machine shows 3.01.

Jun 14, 07 - 11:51 am Comment from: mike

Hey, hey, now the silly un-informed conspiracy folks can come out and say that Apple release Safari 3 on purpose to show that the Mac OS is more secure than Windows
--

Hmm, the thing is, I've heard Win ppl say "Wow, Apple has viruses now that it's marketshare is more than the margin of error"

I mean.. they try to conflate the Stability of OS X and the Stability of a piece of software written for Windows. Idiotic. The funny thing is, in OS X, you can have beta software, and it doesn't matter, because when it crashes it doesn't take your whole system down.

In Windows... er. LOL

So to Windows users, enjoy Safari... it will get much better, very quickly, I assure you the Mac experience of Safari is pretty damn sweet.. .like.. iTunes on a Mac.. and.. say.. MSN Messenger on Windows

wink

Jun 14, 07 - 11:57 am Comment from: Macaday

The REAL results are coming in now - people LOVE Safari on Windows.

It will make great headway. AND this was great advert to show why Apple is more security conscious than Microsoft.

You almost wonder if Apple deliberately put that version out to be able to demonstrate how fast they fix things. MS would have stayed silent for a year or more...

Jun 14, 07 - 12:04 pm Comment from: mike

Speaking of MS, where the FSCK is Office 2008

Jun 14, 07 - 12:19 pm Comment from: did any one repair permission before installing

i did and have only had 1 crash, checking email on gmail. removed the plist, reboot, no probs.

always repair permission when installing new apps, or updates.

this is in mac os x of course, can't comment on xp or vista.

ok i will, friends don't let friends use windows.

Jun 14, 07 - 12:44 pm Comment from: EvangelizeWithRespect

eWorldian, I'm having the same problems and I don't know what's causing it. I'm wondering if it's a conflicting plug-in. Here's my list, from Library / Internet Plug-Ins /. Any overlaps with yours besides the obvious ones?

AdobePDFViewer.plugin
DRM Plugin.bundle
Flash Player.plugin
flashplayer.xpt
Flip4Mac WMV Plugin.plugin
Flip4Mac WMV Plugin.webplugin
ipxBrowserPlugin
Java Applet Plugin Enabler
Java Applet.plugin
JavaPluginCocoa.bundle
NP-PPC-Dir-Shockwave
NPSVG3Carbon
nsIQTScriptablePlugin.xpt
Quartz Composer.webplugin
QuickTime Plugin.plugin
QuickTime Plugin.webplugin
RealPlayer Plugin.plugin
VerifiedDownloadPlugin.plugin
Word Browser Plugin.plugin

Jun 14, 07 - 12:56 pm Comment from: Toby

That's pretty much Apple's MO. Release and quickly fine tune.


And I don't get why browser crashes are Apple's fault? I've sent 5 crash reports last week alone.


Ummm, that was before Safari was released. That was ALL Firefox. That's why Firefox has that (Return to Old Session, Start New Session), buttons when it crashes.

You know, it doesn't take much to become the best browser on PC...not much at all.

Jun 14, 07 - 01:03 pm Comment from: [mmol]

Safari 3.0 also blocks pop-under ads from MDN

Jun 14, 07 - 01:13 pm Comment from: eWorldian

Re: EvangelizeWithRespect

I don't think (at this point) that it's a conflicting Plug-In.
I'm thinking more that the Acrobat PDFViewer plug-in for Safari is simply not compatible with Safari 3.0.

I've sent an email to Adobe, but have yet to hear back.

Jun 14, 07 - 01:22 pm Comment from: Paul Randall

Can some of you guys give my comment defending Safari for windows the thumbs up (positive rating) please?
http://www.computerworld.com/comments/node/9024488
grin

Cheers

Reader feedback page 1 of 2 pages:  1 2 >

Always -- Free ground shipping with orders over $50 at the Apple Store.

Add Your Feedback:

Register or Login

Name:

Email: (optional)

Emoticons | Allowed HTML Tags

Remember my personal information   Notify me of follow-up comments?

Please enter the "MDN Magic Word" you see in the image below:








Current MacDailyNews Stories:

Who will win the great ‘Mighty Mouse’ case?  CBS and Apple or Man & Machine?
Thursday, May 22, 2008 - 03:29 PM EDT
Apple’s AirPort products take 10.6% share of U.S. retail 802.11n WiFi market
Thursday, May 22, 2008 - 02:59 PM EDT
Judge to N.Y. pension fund: No, you still can’t sue Apple over backdated stock options
Thursday, May 22, 2008 - 12:44 PM EDT
Forrester Research predicts Apple products of 2013 as forming ‘credible hub of the digital home’
Thursday, May 22, 2008 - 12:15 PM EDT
eAccess Chairman Semmoto calls Apple iPhone ‘total failure’ in the U.S. market
Thursday, May 22, 2008 - 10:00 AM EDT
Apple CEO Steve Jobs arming customers to take Mac fight to their IT department at work
Thursday, May 22, 2008 - 09:11 AM EDT
FileMaker Pro 9 named Best Database Management Solution in SIIA 2008 CODiE Awards
Thursday, May 22, 2008 - 08:46 AM EDT
Apple releases Logic Pro 8.0.2 Update
Wednesday, May 21, 2008 - 04:34 PM EDT
Canada’s Bell launches Windows-only, non-iPod, PlaysForSure-only video download store
Wednesday, May 21, 2008 - 04:11 PM EDT
Desperate Microsoft to pay people to use its search service
Wednesday, May 21, 2008 - 02:45 PM EDT
iTunes Store ad debuts featuring Coldplay and Apple’s dad (with video)
Wednesday, May 21, 2008 - 02:09 PM EDT
Apple’s $99 per year for .Mac asking too much?
Wednesday, May 21, 2008 - 01:05 PM EDT
Apple to celebrate Grand Opening of Apple Store Pacific Centre (Vancouver) on May 24
Wednesday, May 21, 2008 - 11:51 AM EDT
One-in-ten BBC iPlayer users use Apple Macs; 3 percent use iPhone, iPod touch
Wednesday, May 21, 2008 - 11:06 AM EDT
Apple debuts extended version of ‘Sad Song (Vista Blues)’ ad from ‘Get a Mac’ campaign (with video)
Wednesday, May 21, 2008 - 09:30 AM EDT
Apple and CBS sued for ‘Mighty Mouse’ trademark infringement
Wednesday, May 21, 2008 - 09:25 AM EDT
Associated Press issues retraction: Apple iTunes Store DRM-free is same price as protected tracks
Wednesday, May 21, 2008 - 08:53 AM EDT
Welcome to the So-So: Microsoft to test Zune ads
Tuesday, May 20, 2008 - 06:12 PM EDT
Report: Apple’s next-gen iPhone headed for joint launch in Japan and Korea
Tuesday, May 20, 2008 - 04:44 PM EDT
StopBadware.org coalition calls on Apple to fix Safari ‘carpet bomb’ issue sooner than later
Tuesday, May 20, 2008 - 04:16 PM EDT