Solution: Upgrade to Safari version 4, which fixes the vulnerabilities.
Provided and/or discovered by: 1-3) Tavis Ormandy
4 - 6) Chris Evans of Google Inc.
7) Michal Zalewski of Google Inc.
8) wushi and ling of team509, reported via iDefense
9) Thierry Zoller, reported via ZDI. The vendor also credits Robert Swiecki of the Google Security Team.
10) Alexios Fakos, n.runs AG. The vendor also credits Dino Dai Zovi.
Changelog: 2009-06-10: Added vulnerabilities #5 and #6. Updated credits and "Original Advisory" section. Added CVE references.
2009-06-11: Added vulnerability #7. Updated credits and "Original Advisory" section. Added CVE references.
2009-06-12: Added vulnerability #8. Updated credits and "Original Advisory" section. Added CVE reference.
2009-06-15: Added vulnerability #9. Updated credits and "Original Advisory" section. Added CVE reference.
2009-06-19: Added CVE reference.
2009-06-23: Added vulnerability #10. Updated credits and "Original Advisory" section. Added CVE reference.
2009-07-13: Added CVE reference.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.