# Calendar
You are currently browsing the Stan’s List weblog archives for the day Friday, June 22nd, 2007.
Info End -->
You are currently browsing the Stan’s List weblog archives for the day Friday, June 22nd, 2007.

Marketcircle, maker of Daylite Productivity Suite and Billings business software for the Mac, released iPhoney. iPhoney gives you the opportunity by providing a pixel duplication of a true iPhone. Using the Safari engine iPhoney is able to display a iPhone’s 320 x 480 or 480 by 320 web window. The major difference is that a computer monitor display is generally between 72 and 96 pixels every inch, where iPhone will have 160 pixels. This may require rethinking your design. More …

Actually, you don’t. Marketcircle has not implemented the iPhone’s web zooming function yet in iPhoney–it’s coming soon.

# Security Update 2007-006 |

Security Update 2007-006 is recommended for all users and improves the security of the following component:

*WebCore

CVE-ID: CVE-2007-2401

Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.9 or later, Mac OS X Server v10.4.9 or later

Impact: Visiting a malicious website may allow cross-site requests

Description: An HTTP injection issue exists in XMLHttpRequest when serializing headers into an HTTP request. By enticing a user to visit a maliciously crafted web page, an attacker could conduct cross-site scripting attacks. This update addresses the issue by performing additional validation of header parameters. Credit to Richard Moore of Westpoint Ltd. for reporting this issue.

*WebKit

CVE-ID: CVE-2007-2399

Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.9 or later, Mac OS X Server v10.4.9 or later

Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution

Description: An invalid type conversion when rendering frame sets could lead to memory corruption. Visiting a maliciously crafted web page may lead to an unexpected application termination or arbitrary code execution. Credit to Rhys Kidd of Westnet for reporting this issue. Downloads