You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa Safari

Sigurnosni nedostaci programskog paketa Safari

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: M
  • Kategorije: APL

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256

APPLE-SA-2019-9-26-9 Safari 13.0.1

Safari 13.0.1 addresses the following:

Safari
Available for: macOS Mojave 10.14.6, macOS High Sierra 10.13.6
Impact: Visiting a malicious website may lead to user interface
spoofing
Description: An inconsistent user interface issue was addressed with
improved state management.
CVE-2019-8654: Juno Im (@junorouse) of Theori

Service Workers
Available for: macOS Mojave 10.14.6, macOS High Sierra 10.13.6
Impact: Service workers may leak private browsing history
Description: The issue was addressed with improved handling of
service worker lifetime.
CVE-2019-8725: Michael Thwaite of Connect Media

Additional recognition

Safari
We would like to acknowledge Yiğit Can YILMAZ (@yilmazcanyigit) of
TurkishKit for their assistance.

Installation note:

Safari 13.0.1 may be obtained from the Mac App Store.

Information will also be posted to the Apple Security Updates
web site: https://support.apple.com/kb/HT201222

This message is signed with Apple’s Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/
—–BEGIN PGP SIGNATURE—–

iQIzBAEBCAAdFiEEM5FaaFRjww9EJgvRBz4uGe3y0M0FAl2NGWkACgkQBz4uGe3y
0M1rohAAqaD5bYeP305cUxNucHOv/KOKf6LVk2GK71oLTgIHTGKInLKCD3xZ7Ml/
jOYFbMFDbDyi/lTepa5+yAWcvuB40T7AqstwnG/Ntwzi1LfCRnCHE60lZ/6ACLCC
SB0KRxrhWwgUiZamtSRVeg4ZzDn/5sYwzQgmWx8Oa+/31Ch6TgyvGmljG4vt2Ijx
Vvnvml7IY/glnp53XsmkkvXwr6gOYEA8oFPPaBQnkDQl9voUQhWvZ2HvqZSxJ8NB
Mwj77QOPnNnFNp4Av0CI8tAWZbH6SPpkZZ12OwX2cAyXfa25ptolSOHp51Fs6X+Y
fiOUr1L8ozxTM4vr2MlQYQw6enQ6qyp48hfBWzq6aEpuXJ/BMbfTqnf9rZYdRUpA
Lsxp4CaE6wlrdZXuL2Cj6aiLzvHCiROpGuJrKNBMZqShGjB6q5gTPqWRueeKRH+W
+ywhftihfw+MpiHd56dat+iOFKDfnSmSkRya85sLbN0UNMSJzRb8sdPWBZ2KCwWk
xkyUDaDaVQaEj17FQ18hUrBX38wjpp9yD7nDNcQdr60P0Xm2eCt0lspwiCE3gl1p
DfZiCC1QROE6zIZJktTy9ygZcnBerFY60M7tN0qcf+x6vkfIska+CJChz14qd7+p
ag/jn1JHTThJFRenF1P6W70k8rWsHbv5VuyL9Mih0RX0UVBptes=
=gcEu
—–END PGP SIGNATURE—–
_______________________________________________
Do not post admin requests to the list. They will be ignored.
Security-announce mailing list (Security-announce@lists.apple.com)
Help/Unsubscribe/Update your Subscription:
https://lists.apple.com/mailman/options/security-announce/advinp%40cert.hr

This email sent to advinp@cert.hr

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256

APPLE-SA-2019-9-26-4 Safari 13

Safari 13 addresses the following:

WebKit Page Loading
Available for: macOS Mojave 10.14.6 and macOS High Sierra 10.13.6
Impact: Processing maliciously crafted web content may lead to
universal cross site scripting
Description: A logic issue was addressed with improved state
management.
CVE-2019-8674

Installation note:

Safari 13 may be obtained from the Mac App Store.

Information will also be posted to the Apple Security Updates
web site: https://support.apple.com/kb/HT201222

This message is signed with Apple’s Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/
—–BEGIN PGP SIGNATURE—–

iQIzBAEBCAAdFiEEM5FaaFRjww9EJgvRBz4uGe3y0M0FAl2L4cgACgkQBz4uGe3y
0M140w//SBVeEHScCaFuKyJGGKPaRgwgs9uRPsz8DLgNVny3BCniqhMnQPHeDWKI
zjhd+M2oZvvaplPvFUXhjJutA9TTaX1HgVRW05j91OOtXz/FeSK1475KLXiWbrMl
MsMq4u3HSjj36G78ShvRoLAPdG8qTubqPXikQ4E2nYIhjF8uEFYfH+Vfq+kJFJ4h
e3QF7AfPiy/TTrLk9uBFlJGcqZ6CC1ySEDIaMmxqdYGaBZW85w6auM0hTLbJ51fw
YChKpzlfDg3s4oAtifHjHCP8jwH47uitlWrvOo3yjlI/oMeS3FSDUYmgFzGUv7DU
aSrz6Pfqpj38A8ln5ZfyHsQmU94oaDfJZ6TCcuILyJsDEoIRQH5n1KyuXkbCDvHO
p64tUZOJtspRSce8dIa0XgP8jruK1N4IH3Td1AzkWRdSIPvAo6+n+XJGgRzFrs2S
yDNKrqgAlnGuGz/uPY4YSy84cBP8qNjNEGDGngpTKtLboDpwiWF5Xsjshua21xov
OredEXzYKjL2OYbHI23xCtGJ5zCVST63awdEsAELmPlWTEgv1/Cnl3ZnnzTYurx9
FUBxtBmbpYWf2swjqauhD7atfYLE1lyyaE3F/jAd9YrZeyVqMHNLU9+G03OwcUe3
xl9XxykQzUm4mBokPlhC0Bw1n/MMxbOdxkwV2N6n63XTE2vR5/0=
=Inji
—–END PGP SIGNATURE—–

_______________________________________________
Do not post admin requests to the list. They will be ignored.
Security-announce mailing list (Security-announce@lists.apple.com)
Help/Unsubscribe/Update your Subscription:
https://lists.apple.com/mailman/options/security-announce/advinp%40cert.hr

This email sent to advinp@cert.hr

AutorToni Vugdelija
Cert idNCERT-REF-2019-09-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostatak programskog paketa dcmtk

Otkriven je sigurnosni nedostatak u programskom paketu dcmtk za operacijski sustav Fedora. Otkriveni nedostatak potencijalnim napadačima omogućuje izazivanje DoS stanja...

Close