IT NEWS      Sustainability        - Virtualisation   
Technology news and Jobs arrow Information Technology News arrow Bumper bundle of security patches for Mac OS X
Bumper bundle of security patches for Mac OS X PDF E-mail
User Rating: / 3
PoorBest 
by Stephen Withers   
Wednesday, 19 December 2007
Apple's Security Update 2007-009 delivers a wide-ranging set of fixes for Leopard and Tiger.

The update covers the desktop and server versions of Mac OS X 10.4.11 and 10.5.1, and many of the issues allow the execution of arbitrary code.

Several items relate to third-party or open source software provided with Mac OS X.

Adobe's Flash Player plug-in 9.0.115.0 and Shockwave plug-in 10.1.1.016 are included. While the former was released earlier this month, Adobe's web site says the latter appeared in March 2006. The Shockwave plug-in provided with Mac OS X 10.5 describes itself as version 10.1r11 with a 2004 copyright date. It is surprising it took so long for Apple to distribute the 'new' version.

Other examples include new versions of the Python, Perl and Ruby interpreters, Samba (which provides Mac OS X's SMB file and printer sharing capabilities), CUPS (the open source Common Unix Printing System, now 'owned' by Apple), the GNU Tar utility (used to create and unpack certain types of archive files), and tcpdump (a network monitoring tool; the update provides version 3.9.7, not the current 3.9.8)

The problem with Apple distributing non-current versions of open source software is that it makes it easier for attackers to find holes in Mac OS X. They can look for any security-related changes between the versions, and then work out ways of exploiting them.

Most of the fixes relate to Apple's own software, including Address Book, ColorSync, iChat, Mail, Quick Look, Safari, Software Update and Spotlight. They generally involve maliciously crafted files or links causing crashes or arbitrary code execution.



 
< Next story in category   Previous story in the category >
iTWire Technology feature

Virtualisation

Servermaximise your infrastructure, maximise your business

Read more...

Custom Search
 
You don't need to login to post a comment





Lost Password?
No account yet? Register
Subscribe to our free daily newsletter.
BCI Training – Understanding BCM Principles and Good Practice
August 23, 2008 (All Day)
BCI Training – Understanding BCM Principles and Good Practice consists of 5 one day training modu...

BCI Training – Understanding BCM Principles and Good Practice
August 24, 2008 (All Day)
BCI Training – Understanding BCM Principles and Good Practice consists of 5 one day training modu...

BCI Training – Understanding BCM Principles and Good Practice
August 25, 2008 (All Day)
BCI Training – Understanding BCM Principles and Good Practice consists of 5 one day training modu...

BCI Training – Understanding BCM Principles and Good Practice
August 25, 2008 (All Day)
BCI Training – Understanding BCM Principles and Good Practice consists of 5 one day training modu...

HP QuickTest Professional Public Training
August 25 (9:00 am) - August 26 (11:59 pm), 2008
This instructor-led course provides a comprehensive understanding of using QuickTest Professional...

NICTA Big Picture Seminar - Dr Rodney Brooks "Robotics: Shaped by and Shaping the World in 2000 - 2050"
August 25, 2008 (4:00 pm - 5:00 pm)
ABSTRACT: As the 21st century has dawned we have seen a dramatic uptake of robots for unstructure...

BCI Training – Understanding BCM Principles and Good Practice
August 26, 2008 (All Day)
BCI Training – Understanding BCM Principles and Good Practice consists of 5 one day training modu...

BCI Training – Understanding BCM Principles and Good Practice
August 26, 2008 (All Day)
BCI Training – Understanding BCM Principles and Good Practice consists of 5 one day training modu...

PR Online
August 26, 2008 (9:30 am - 12:00 pm)
PR Online Sydney, August 26, 2008 Speakers: - Michael Henderson, Specrum PR - Jeremy Mitche...

ICT SMART: OFFICE SHOW
August 26 (10:00 am) - August 28 (11:59 pm), 2008
ICT SMART office show, is a business-to-business trade event featuring the latest in business tec...
New event listings
SolidWorks Innovation Day (Melbourne and Adelaide)
October 17, 2008 (All Day)
Hosted by Intercad, SolidWorks’ Innovation Days will give designers, engineers and manufacturers ...

SolidWorks Innovation Day (Sydney)
October 16, 2008 (All Day)
Hosted by Intercad, SolidWorks’ Innovation Days will give designers, engineers and manufacturers ...

SolidWorks Innovation Day (Brisbane and Perth)
October 15, 2008 (All Day)
Hosted by Intercad, SolidWorks’ Innovation Days will give designers, engineers and manufacturers ...

LIXI Industry Forum 2008
September 10, 2008 (All Day)
Wednesday, 10 September 2008 The Westin Sydney The second annual major industry event for the...

BCI Training – Understanding BCM Principles and Good Practice
August 22, 2008 (All Day)
BCI Training – Understanding BCM Principles and Good Practice consists of 5 one day training modu...

BCI Training – Understanding BCM Principles and Good Practice
August 21, 2008 (All Day)
BCI Training – Understanding BCM Principles and Good Practice consists of 5 one day training modu...

View Full Calendar
Subscribe to our free daily e-newsletter
Contact , Register , Advertise with iTWire , Links , About iTWire , Feedback , Post your jobs , Events , iTWire site map , Start Blogging , MyBlogLog page
Industry Releases , Submit your release now