ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Zero-day flaws surface in Apple Safari

By | March 1, 2010, 10:59am PST

Over the last two weeks, security researchers have reported eight different zero-day vulnerabilities in Apple’s Safari browser.

Details of these vulnerabilities, all rated “high risk,” have been sold to Tippingpoint’s Zero Day Initiative (ZDI), a program that purchases the rights to vulnerability information in exchange for exclusivity to broker fixes with affected vendors.

[ SEE: Pwn2Own 2009: Safari/MacBook falls in seconds ]

A high-risk rating is used to describe a vulnerability that could be exploited to launch remote code execution (drive-by download attacks).

All eight of the Safari vulnerabilities were reported by a researcher named “wushi” of team509.  ZDI’s Upcoming Advisories page provides a basic listing of the vulnerabilities alongside a running count of the number of days it was number of days they were reported to Apple.

follow Ryan Naraine on twitter

The page also lists outstanding flaws in software products offered by Adobe, Mozilla Firefox, Novell, Hewlett-Packard, Oracle, Microsoft and IBM.

TippingPoint ZDI is the sponsor of the annual CanSecWest Pwn2Own hacker contest, where the Safari browser is usually a very big (weak) target.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues.

Disclosure

Ryan Naraine

The most important disclosure is of my employment with Kaspersky Lab as a member of the global research and analysis team. Kaspersky Lab is a global company specializing in anti-malware and secure content management technologies. I do not own stocks or other investments in any technology company.

Biography

Ryan Naraine

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the globe. He is taking a leadership role in developing the company's online community initiative around secure content management technologies.

Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.

Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?
49
Comments

Join the conversation!

Just In

RE: Zero-days flaws surface in Apple Safari
FAULKNE 13th Oct
Good day to confirm this comment I would appreciate T h e b e s t o f Z D N e t d e l i v e r e d your website very nice to everyone Yes, Oracle is the only one with shared-disk architecture, but that is there advantage. It means you can add or remove nodes and the database lives on. In a shared nothing architecture, if you lose a node, you lose the system. I'm sure Oracle appreciates EMC highlighting their advantage.I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate Awesome post! Thank you very much || thanks for nice content this is really benefit to me.
0 Votes
+ -
Severity: high, high, high, high, high, high, high, high
honeymonster Updated - 1st Mar 2010
Why am I not surprised. And still no sandboxing of
this swiss cheese browser?
0 Votes
+ -
Agreed
Pete "athynz" Athens 1st Mar 2010
Though it would be interesting to know if this affects ALL versions of Safari or just Windows or just Mac... The article did not mention that.
0 Votes
+ -
Note 4 Long
i_made_this 1st Mar 2010
A. Chrome browser as base for an eventual "Chromium Operating System For Desktops / Laptops" (cf chromium dot org) is coming very soon. As you know, the Chrome browser and Google's small form operating systems have been here for awhile.

B. Mozilla Firefox browser as base for an eventual "Firefox Operating System" is also in development (cf Mozdev blogs). There is no indication of RTM release dates yet, but that doesn't mean the for-profit Mozilla Corp hasn't been aggressively developing their own O/S in the slightest.

C. Opera's browser is already core to a number of enterprise level Linux distributions, just as Firefox is to a number of Education / SMB / Home and Home Office level Linux distributions.

GOOG's will be a proprietary O/S - it already is in its small form factor versions.

It's too early to tell if the mentioned FF O/S and Opera O/S will be propriety. Based on FF's resounding success as the pre-loaded browser in the popular Linux Ubuntu operating system, tells us nothing on that score.

If anything, the poor experience with Ubuntu's high powered audio / visual proprietary drivers running Nvidia processors including the CUDA technology infers that ATI should have handled the product development from the outset.

The fact that Nvidia has no comment on their failed 2007 project working with Canonical infers that ATI got the nod back then to take this over so they clearly cannot comment on their on-going development to build hardware better suited to the Linux distributions including Ubuntu and others that are desperately needed by the Government, Education, Science, Architecture and Enterprise sectors.

This means the substantial funding to support AMD / ATI's work in Linux has certainly been there from the mentioned sectors following AMD's purchase of ATI and the AMD / ATI cutting edge fab recently constructed in upstate New York.
0 Votes
+ -
there "Because IE and Safari only exist to download Firefox, Opera, and/or Chrome."

What kind of delusional world do you live in?

References: http://marketshare.hitslink.com/report.aspx?qprid=0

Microsoft Internet Explorer 61.58%
Firefox 24.23%
Chrome 5.61%
Safari 4.45%
Opera 2.35%
Netscape 0.75%
Opera Mini 0.64%
Mozilla 0.14%
Flock 0.06%
ACCESS NetFront 0.04%
Playstation 0.04%
Konqueror 0.03%
Obigo 0.01%
Danger Web Browser 0.01%
Microsoft Pocket Internet Explorer 0.00%
Blazer 0.00%
WebTV 0.00%
Lotus Notes 0.00%
BlackBerry 0.00%
iCab 0.00%

Report generated Monday, March 01, 2010 10:11:19 PM

~~~~~~~~~~~~~
Insanity: doing the same thing over and over again and expecting different results.
~ Albert Einstein
0 Votes
+ -
The real world. And you?
AzuMao 1st Mar 2010
According to w3schools IE only has %35.


And I bet that 35% is comprised mainly of the geriatric community.
OK, provide credentials for your sources?

http://www.netapplications.com/company.aspx
OUR COMPANY

Our History
Since 1999, Net Applications has been a leading source of applications for webmasters and eMarketers. Headquartered in Aliso Viejo, California, Net Applications has over 3 million registed users and distributes its services through 8,000 partners and affiliates. These services may also be found at:
?HitsLink Web Analytics
?NetMarketShare Internet Market Share Data
?Surveyware Online Surveys
?LoadDNS Managed DNS
?1stWarning Site Monitoring
?SearchTerms.com Search Terms Optimizer
?SharePost Social Bookmarking

Our mission is to create a ecosystem of world-class applications in conjuction with the world's best partner base.


Net Applications Management Team
Click here to contact us!


Our Facilities

We have partnered with AT&T for our state-of-the-art facilities that can support the security and performance of the most demanding customer needs.



?Triple redundant internet bandwidth
?Conditioned power and redundant backup power generators
?24x7 secure access
?Smoke detection and fire suppression systems
?Video camera surveillance
?HVAC temperature control systems
?Seismically braced racks


Our Headquarters
Net Applications
65 Enterprise
Aliso Viejo, CA 92656


Who is w3schools? As for the geriatrics comment, it speaks volumes about your willfullness and immaturity...

~~~~~~~~~~
Who you are speaks so loudly I can't hear what you're saying.
~ Ralph Waldo Emerson
OK, provide credentials for your sources?

http://www.netapplications.com/company.aspx
OUR COMPANY

Our History
Since 1999, Net Applications has been a leading source of applications for webmasters and eMarketers. Headquartered in Aliso Viejo, California, Net Applications has over 3
million registed users and distributes its services through 8,000 partners and affiliates. These services may also be found at:
?HitsLink Web Analytics
?NetMarketShare Internet Market Share Data
?Surveyware Online Surveys
?LoadDNS Managed DNS
?1stWarning Site Monitoring
?SearchTerms.com Search Terms Optimizer
?SharePost Social Bookmarking

Our mission is to create a ecosystem of world-class applications in conjuction with the world's best partner base.


Net Applications Management Team
Click here to contact us!


Our Facilities

We have partnered with AT&T for our state-of-the-art facilities that can support the security and performance of the most demanding customer needs.



?Triple redundant internet bandwidth
?Conditioned power and redundant backup power generators
?24x7 secure access
?Smoke detection and fire suppression systems
?Video camera surveillance
?HVAC temperature control systems
?Seismically braced racks


Our Headquarters
Net Applications
65 Enterprise
Aliso Viejo, CA 92656


Oh no.. lots of bandwidth, generators, air conditioners, fire alarms, video cameras, and braces? Well I guess you win then.

W3Schools is just one of the biggest web-related resources, and only since 1998. sad

As for the geriatrics comment, it speaks volumes about your willfullness and immaturity...

That they don't understand nor care much about computers and thus stick with whatever comes installed?
Maybe I am too nice to service the needs of
friends / relatives / neighbors / coworkers when
their XP / Vista has issues...

I have tried to explain safe computing and most
have a glazed look and drool haha - I try to
install other browsers or mail clients, nope
they have to have IE6 and outlook express. It's
sad really, but as long as they buy the pizza
and beer more power to them (and to malware
authors)
0 Votes
+ -
So what now?
OhTheHumanity 1st Mar 2010
Apple did not find these and so these are working vulnerbilities that could be in the wild. I guess we can all put to rest that your Apple is bulletproof.
0 Votes
+ -
straw man
gigogogogown 1st Mar 2010
Who thinks or who ever said that Apple is bulletproof?

The fact is that security compromises exist far more on the Microsoft Windows platform. Even if it is more secure, it is the most compromised platform. And it may be due to gullible users falling for social engineering tricks, which could happen on any platform.
But at least in my support arena (University campus), I am constantly dealing with cleaning up compromised Windows computers. Even with anti-virus software installed.
0 Votes
+ -
Trolleur did. He posted below you.
GuidingLight 1st Mar 2010
happy
0 Votes
+ -
okay, i stand corrected...
gigogogogown 1st Mar 2010
only trollers claim OS X is "bulletproof". Thus, we still have a straw man.
0 Votes
+ -
No, "we" don't.
ye 1st Mar 2010
only trollers claim OS X is "bulletproof". Thus, we still have a straw man.

Can't blow it off because he might be a troll.
0 Votes
+ -
Wake me up...
Trolleur 1st Mar 2010
Please wake me up when there is a worm in OS X
from these vulnerabilities. If this was Microsoft,
half the world would be infected now.

The truth of the matter is that OS X is
bulletproof.
0 Votes
+ -
....
Badgered 1st Mar 2010
The truth of the matter is that OS X is
bulletproof.


Perhaps... "ignored" is the term you were looking for?
0 Votes
+ -
NonZealot got a new nickname? [nt]
olePigeon 1st Mar 2010
[nt]
0 Votes
+ -
Probably....
Badgered 1st Mar 2010
If so, he also got a lot more sarcastic.
0 Votes
+ -
Who is NonZealot? {nt}
WinTard 1st Mar 2010
.
0 Votes
+ -
Keep it up.....
OhTheHumanity 1st Mar 2010
You said exactly what my post said you people say. Im not here to state who is more secure or not. Your just the arrogant type that thinks you are immune and so it makes you more vulnerable. This guy exploited vulnerabilities and so has Apple when it releases patches for remote code execution holes so don't act like it can't happen.

Apple patches much more than Windows and Windows Vista + is more secure than OSX. Running as admin in XP was the first mistake from microsoft on that OS. There are others but I advise to move on just as Apple wants you to move on as well. Same thing just different name but you think some how it is different.
0 Votes
+ -
Mac OSX is bulletproof? Really?
Pete "athynz" Athens 1st Mar 2010
because this:http://blogs.zdnet.com/security/?p=2917 says otherwise... and nowhere in the article did it say it was a Windows thing - just a Safari thing.
0 Votes
+ -
What platforms?
sj2@... 1st Mar 2010
What platforms does it affect? MacOS and iPhone OS?
0 Votes
+ -
Windows
AzuMao 1st Mar 2010
0 Votes
+ -
Complete BS!
Trolleur 1st Mar 2010
Everyone knows Apple is more secure than Windows. Windows
users are under attack EVERY MINUTE that they're online.
These Apple vulns must be bogus.
0 Votes
+ -
Apple is a company.
AzuMao 1st Mar 2010
Safari is a Firefox/Opera/Chrome downloader, just like IE is.

No need to use it after its fulfilled its purpose, so vulnerabilities in it are irrelevant.
0 Votes
+ -
@Trolleur
Axsimulate 1st Mar 2010
I used both everyday and I prefer OS X over Windows, however that being said, you are giving Mac users a bad name with your wild claims.
0 Votes
+ -
Ahh, blind faith is so empowering!
WinTard 1st Mar 2010
Speaking of which between Jan 1 2010 and March 1 2010, there were 46,806,500 brand new PCs sold to date this year.

I wonder how many were Apple's?

http://www.worldometers.info/computers/

Of course, EVERY MINUTE counts!
0 Votes
+ -
From Form 10-K/A Page 10
Jkirk3279 1st Mar 2010
Mac unit sales for 2009:

10,396,000 computers, (not counting iPhones or iPod
Touch.)

Net sales per unit $1,333.00

Unfortunately IDC's Powerpoint link for the full report
isn't working.
0 Votes
+ -
Interesting, thanks
WinTard Updated - 1st Mar 2010
BTW what follows is with all due respects: I appreciate your goodwill answer in providing solid info.

I also must state for the record Apple machines are good, solid systems, well designed, and oh so sexy...

Alas, however to make my case, I must also point out the some of reverse side of the 'coin'.

Simple math implies:

866,333 / month X 12 months = 10,396,000 units.

So in the first two months of 2010 we can extrapolate that at least 866,333 * 2 = 1,732,666 brand new Apple Macs were sold?

Hmmm, okay, ratio from 46,806,500 brand new PCs sold to date this year versus 1,732,666 for Mac PCs would indicate a ratio of 0.037017636439383418969587557283711 or about 3.7% of the market?

Hey, that's even more than all of Linux combined! Not bad.

References? http://marketshare.hitslink.com/operating-system-market-share.aspx?qprid=8

Ouch about the average $1333 price however, unless you look at it from Apple's shareholder perspective, and not a mere Apple Mac enthusiast buyer?

Hmmm, let's see what $399 buys you today?

64-bit Quad core CPU, 8GB RAM, 750GB Sata 3Gbps HDD? For a brand-new desktop, hmmmm....
http://www.tigerdirect.com/email/WEM2184.asp?SRCCODE=WEM2184TT&cm_mmc=Email-_-Main-_-WEM2184-_-tigeremail

How about a brand-new ultra-portables such as the Dell Vostro 13, $450 and thinner (and also aluminum) than an $1499 Apple MacBook Air?

Google: http://www.google.com/search?q=vostro+13
Results 1 - 10 of about 13,200,000 for vostro 13. (0.53 seconds)

Well, that explains why so many (about 96%) of new PCs sold are not Apple?

If that is the case, perhaps whoever said:

2.2.1. ....
Badgered - 03/01/10

The truth of the matter is that OS X is
bulletproof.

Perhaps... "ignored" is the term you were looking for?


Was onto something?

Now if Apple Macs (and Linuxes) are being simply being ignored, does that make them more secure in any way?

Hmmm, food for thought?

~~~~~~~~~~~~
Don't judge a man by his opinions, but what his opinions have made of him.
~ Georg Christoph Lichtenberg

Judge a man by his questions rather than by his answers.
~ Voltaire, 1694-1778, French Writer and Philosopher
0 Votes
+ -
Re: Hey, that's even more than all of
AzuMao Updated - 1st Mar 2010
Not according to W3Schools, who are far more well-known.


Also, are you sure that 46,806,500 figure is just from the beginning of 2010 to now, rather than the last 12 months?
0 Votes
+ -
Or so you say... Pfft!
WinTard Updated - 1st Mar 2010
Not according to W3Schools, who are far more well-known.

Than what? Just because you say it? How many customers do they have? Which big name customer do they have? What credibility does W3Schools have other than being a bunch of amateurs doing this for fun? Oh I see, it's a Web Developer's Portal. A Web Forums? Serious indeed...

Substantiate! Links! Prove it! Or else it's all BS and lies!

And BTW, the link you provide is completely useless, doesn't answer any of the questions I asked... Regarding customers, the credibility and methods used to collate metrics...

As to the number of new computers sold this year in 2010:

http://www.worldometers.info/computers/
Computers sold this year:
46,983,515

Computers sold in the world - sources and methods
The source for this data is IDC, the premier global provider of market intelligence, advisory services, and events for the information technology, telecommunications, and consumer technology markets.

IDC's Worldwide Quarterly PC Tracker gathers PC market data in 55 countries by vendor, form factor, brand, processor brand and speed, sales channel and user segment. The research includes historical and forecast trend analysis as well as price band and installed base data.

The PC tracker includes Desktop, Notebook, Ultra Portable, and x86 Server market data. It does not include handhelds.



Laptop Computers vs. Desktop Computers
The market is moving toward portable PCs even faster than expected.
According to IDC, the laptop share of client PCs is expected to reach 50% by the end of 2008.



How many computers are there in the world?
According to Gartner Dataquest's statistics, in April 2002 the billionth personal computer was shipped. The second billion mark was supposedly reached in 2007.

But how many computers are actually in use? According to a report by Forrester Research, there will be over one billion PCs in use worldwide by the end of 2008.

And with PC adoption in emerging markets growing fast, it is estimated that there will be more than two billion PCs in use by 2015, Forrester predicts. Therefore, whereas it took 27 years to reach the one billion mark, it will take only 7 to grow from 1 billion to 2 billion.




References and useful links:

?IDC - the premier global market intelligence firm


?Gartner Dataquest - leader in providing the high-technology and financial communities with market intelligence for the semiconductor, computer systems and peripherals, communications, document management, software and services sectors of the global information technology industry



?printer cartridges


?micr toner


?printer cartridges


?Forrester Research - independent technology and market research company that provides pragmatic and forward-thinking advice to global leaders in business and technology.


?ComputerWorld: Laptops fuel strong worldwide PC sales, says IDC


?SIA - Semiconductor Industry Association


Am I sure this number refers to the number of computers sold this year 2010? Yes I am sure!

http://www.worldometers.info/faq.php#year
What does "this year" refer to?
Counters are reset to zero at the beginning of each solar year (January 1). Therefore "this year" refers to the period from January 1, 2009 (00:00) up to the moment (day and time) when you visit the site.


Obviously they forgot to update FAQ this year? But substantiating info here:

Number of computers sold worldwide in 2009 rose ? Gartner
admin
NEW YORK (AFP) ? Worldwide, 2009, more computers have been purchased as the previous year. The number of sales of PCs and laptops grew by 5.2% to 306 Million units, such as the U.S. service sector by Gartner on Wednesday (Local time) told. After that first year, the weak Plus a worldwide significant increase in sales in the last quarter owe.
The U.S. company Hewlett-Packard defended the information According to nearly 59 million computers sold (up 11.3%), its position as Leader. The Taiwanese manufacturer Acer increased its sales by 29.4% to almost 40 million, relegating the U.S. company of Dell second place, which sold about 37 million PCs and laptops (minus 9.1%).
DJG / jhe
END) Dow Jones Newswires
January 14, 2010 04:46 ET (09:46 GMT)
http://www.fortune500global.com/news/number-of-computers-sold-worldwide-in-2009-rose-gartner/


Now don't take my word for it. Check it out yourself! And learn something real for a change.

~~~~~~~~~~~
The greatest obstacle to discovery is not ignorance - it is the illusion of knowledge.
~ Daniel J. Boorstin
As for yours.. nowhere on that page does it say whether by year it means the last 3 months or the last 12 months.
0 Votes
+ -
Well, now, wasn't it nice that they didn't explain the nature of the vulnerability so I can avoid it until a patch comes out?

Would it kill them to give a hint of whether it's a site or a setting or SOMETHING that might be avoided until patched?
0 Votes
+ -
Basically..
AzuMao Updated - 3rd Mar 2010
..the first vulnerability is when you download a certain malicious file, run it, and give it admin, bad stuff happens.

..the second one is when you download a different malicious file, run it, and give it admin, bad stuff happens.

..the third one is when you download an even more different malicious file, run it, and give admin, bad stuff happens.

..the forth one is when you download an even more different malicious file, run it, and give it admin, bad stuff happens.

..the fifth one is when you download an even more different malicious file, run it, and give it admin, bad stuff happens.

..the sixth one is when you download an even more different malicious file, run it, and give it admin, bad stuff happens.

..the seventh one is when you download an even more different malicious file, run it, and give it admin, bad stuff happens.


..the eighth (and worst) one is when you go to Microsoft.com and it asks you to download IE and you run it.
If you do this, your computer instantly explodes, killing everyone in a 50 mile radius. Even without admin privileges.
0 Votes
+ -
Over and over, the same problem on ZDNet.

Pathetic.
0 Votes
+ -
It means..
AzuMao 6th Mar 2010
.. this.

Over and over, you Luddites keep having the "waaaah searching is too hard!" problem.

Pathetic.
0 Votes
+ -
RE: Zero-days flaws surface in Apple Safari
efsane Updated - 8th Apr 2011
Great!!! thanks for sharing this information to us!
sesli sohbet sesli chat
0 Votes
+ -
I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate! nccma cooler
0 Votes
+ -
I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post. this thread is amazing i like your work and i appreciate you that you have share a useful stuff thanks for sharing the i shop abatwa
0 Votes
+ -
I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post.Bookmarking now thanks please consider a follow up post. power sa shop
0 Votes
+ -
I think the representation of this article is actually superb one. This is my first visit to your site. Thanks a lot and keep sharing the information. Keep updating the information for all of us. Thanks ZDNet Government was launched as the brand's first industry vertical, with a mission to cater to IT professionals in the public secto I agree with your post. However, do you have any sources I can cite for my paper wheel car com bury
Well welcome, hopefully you can become a vital member of the community and really help to push far ahead of google. Which Im sure the development team would love. This will of course earn you alot points too and get you on the leaders board. z d n e t t h a n k Im not sure i come to an agreement with you on every level, howevor it absolutely was a good posting, many thanks for taking the time to put up your ideas.
This is my first visit to z d n e t site. Thanks a lot and keep sharing the information. Keep updating the information for all of us.how can i clean up, because i don???t know why it seems my skeen has to fat i get the glasses dirty every day.i search y a h o o Very good quality indeed. I surely recommend it. The template used in their site is also great.
Fantastic news about the new release.I positively enjoying each little bit of it and I have you b o o k m a r k e d to check out new stuff you weblog post.Im not sure i come to an agreement with you on every level, howevor it absolutely was a good posting, many thanks for taking the time to put up your ideas
Good day to confirm this comment I would appreciate T h e b e s t o f Z D N e t d e l i v e r e d your website very nice to everyone Yes, Oracle is the only one with shared-disk architecture, but that is there advantage. It means you can add or remove nodes and the database lives on. In a shared nothing architecture, if you lose a node, you lose the system. I'm sure Oracle appreciates EMC highlighting their advantage.I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate Awesome post! Thank you very much || thanks for nice content this is really benefit to me.

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix