Follow the Australian Telecommunications scene NEWSLETTER- FREE TRIAL
Core Dump
Core Dump RSSStephen Withers turns his gaze on the world of Apple, with detours into other aspects of IT and communications as they catch his attention.
Technology news and Jobs arrow Our Blogs arrow Core Dump arrow Mac OS X 10.5.6 - this time it's real
Mac OS X 10.5.6 - this time it's real E-mail
by Stephen Withers   
Tuesday, 16 December 2008
As for the security aspects of 10.5.6 and Security Update 2008-008 for Tiger, several of the issues concern improved error checking to avoid problems that could be caused by maliciously crafted files.

Such file types include PDF (Leopard only), CPIO archives, image files generally, Flash content, and ISO images.

There's also a cookie-related issue in Safari that could allow the disclosure of user credentials.

Download validation (Leopard only) has been improved so that files with executable permissions and no specific application association are marked as potentially unsafe.

Changes have been made to various system calls and APIs to avoid privilege escalation, denial of service attacks, and arbitrary code execution. Leopard Server's Podcast Producer has been changed to prevent remote attacks via its administrative functions.

One unusual correction concerns Leopard's Managed Client feature. On systems that lack built-in Ethernet (and the only recent Mac that fits that description is the MacBook Air) certain screen saver settings are not correctly applied, including the lock.

Mac OS X 10.5.6 Update and Security Update 2008-008 are available via Software Update or from Apple's Support Downloads page.

File sizes range from 72M for the PowerPC version of Security Update 2008-008 to 883M for the 10.5.6 Server combo update.

If your 10.5.5 system is otherwise up to date, Software Update may be able to fetch a smaller version of the 10.5.6 updater.

Powered By Joomla Tags

Please enable JavaScript in your browser to post your comment!



 
< Next story in category   Previous story in the category >
iTWire user statistics Visitors last 30 days
694,279
Subscribers 15,210
#1 independent technology news advertise here
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff

- Advertisement -

Featured Whitepapers

Follow iTWire on Twitter

About iTWire

iTWire is all about technology news, information, jobs and community for the IT and telecommunications industry professional. Subscribe to our free ICT daily newsletter