Saturday | 6 September, 2008
Computerworld
Apple issues monster security patch
Matthew Broersma (Techworld.com) 05/05/2005 11:43:07

Computerworld Buyer's Guide - Vendors Matched to this Article
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualisation technologies, products, news and features.
RSS Feeds

Apple Computer has released its second major security update in as many weeks, fixing 20 bugs in the "Jaguar" version of the Mac OS X operating system. The most serious of the flaws could allow remote attacks, Apple said.

This week's patch is designed for desktop and server versions of OS X 10.3.9, an update released in mid-April as Apple geared up for the launch of OS X 10.4, nicknamed Tiger. Software vendors often patch a large number of bugs in new software releases, then issue a patch fixing the same bugs in older versions of the product.

The flaws patched this week are more serious than those addressed by the April patch, with some of the new bugs allowing remote attackers to run malicious code on a user's system. A buffer overflow in Apache's htdigest program could be triggered via a CGI application to allow remote system compromise, Apple said.

An integer overflow in AppKit could allow for malicious code execution via malformed TIFF images; two flaws in the libXpm library could allow code execution via another image format, XPM, although Apple noted that libXpm isn't installed by default.

A bug in the Foundation framework's handling of an environment variable could result in a buffer overflow, allowing the execution of code, Apple said. Help Viewer could be commandeered by remote attackers to run Javascript without the usual security restrictions. A buffer overflow in NetInfo's Setup Tool (NeST) could also allow remote code execution.

Other flaws are not so serious, allowing attacks by local users, or allowing users to escalate their privileges. Affected programs include AppleScript, Bluetooth, Directory Services, Finder, LDAP, lukemftpd, Server Admin, sudo, Terminal and VPN, Apple said in its advisory, available here. Apple has been criticized in the past for playing down security problems, but has improved in recent months, according to security experts.

Patches are available through the Mac's built-in software update system or from Apple's Web site. Independent security firm Secunia gave the flaws a "highly critical" rating.

Separately, some software makers have reported that some networking applications don't work properly with Tiger, blaming changes to the operating system core, or kernel. Cisco said last week that its VPN client wouldn't work with Tiger. This week vendors such as Thursby Software, Microsoft, Lobotomo Software and Equinux said that some of their VPN and networking software is either completely or partly broken by Tiger, according to reports. Apple has said it is working with vendors on fixes.

Computerworld Buyer's Guide - Vendors Matched to this Article
Market Place

Computerworld Member Login


 

Prioritizing Services with IT Service Management (ITSM)

Computerworld Live Webinar
Wednesday 20th, August 2008
11:00am EST (Sydney, Australia)

To be repeated on:

Thursday 4th, September 2008
11:00am EST (Sydney Australia)

Sign up and receive a free copy of The Forrester WaveTM Service Desk Management Tools, Q2 2008 at the conclusion of the Webinar.

Attend and discover:

  • How to deliver value to your business through ITSM
  • Best practice ITSM implementation
  • Why emphasis is changing from optimizing IT management processes to better servicing customers and demonstrating real dollar value
  • If service-oriented ITSM is best for your business
Whitepaper

An EMC Perspective on Data De-Duplication for Backup

Explore the factors that are driving the need for de-duplication and the benefits of data de-duplication as a feature of an organizations backup strategy.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links