utilities/system updates

08/15/2005, 5:15pm, EDT

Monday, August 15th

Apple patches 34 exploits with latest security update

Apple today released Security Update 2005-007 for both client/server versions of Mac OS X 10.3 Panther (client/server) and Mac OS X 10.4 Tiger (client/server). Apple says the update delivers a number of security enhancements and is recommended for all Macintosh users. It includes updated components for Apache 2 (Server version only), AppKit (2), BlueTooth, CoreFoundation, cups printing service, Directory Services, HIToolBox, Kerberos authentication, Apple's loginwindow, several Mac OS X Server components, Mail.app email client, MySQL (Server-only), OpenSSL sysetm security layer, ping/traceroute networking tools, QuartzComposerScreenSaver, Security, Interface, Safari web browser, SquirrelMail mail server (Server only), X11 windowing system, WebKit (Tiger-only), Weblog Server (Tiger Server only) and zlib compression library.


Filed under: software

, , 7comments, del.icio.us, slashdot, digg, buzz


7 comments
Reader Reactions (Please use <i></i> for italic text)

subscribe to comments
for this article




Expand All   Global Settings
34???
0
08/15, 5:37pm, EDT
WTF? Apple hire MS programmers recently. Its been a long time since MS has fixed 34 security holes in one sitting. Maybe if Apple spent more time evaluating and scrutinizing code (and finishing it, for goodness sakes) then trying to add as many unfinished whiz-bang features, we wouldn't have to have all these security updates.
Fresh-Faced Recruit
Joined Aug 2001
User is offline
Exploits?
0
08/15, 5:56pm, EDT
34 exploits? Or vulnerabilities? There's a world of difference; most of what I see described in the notice are buffer-overflow "vulnerabilities", which are frequently only hypothetical, since actually exploiting a buffer overflow requires a bunch of other things to go right (for the bad guy). An "exploit" is a documented, reproducible way to take advantage of the vulnerability, and is a much more scary thing.

I think too many people are prone to use the words interchangeably, and thereby (as in this case) overstate the danger.

Buffer overflows are probably one of the most common programming errors made in C/C++; such vulnerabilities, when found, should be corrected, even if there is no known exploit. But please let's be careful in describing what Apple is fixing here.
Fresh-Faced Recruit
Joined Aug 2004
User is offline
perspective
0
08/15, 7:15pm, EDT
Apache CUPS LDAP Kerberos MySQL OpenSSL Squirrelmail X11 (XFree86/xorg) zlib

Are all services that Apple simply bundles and/or wraps a GUI around. Apple does not write or maintain code for these projects.
Clinically Insane
Joined Mar 2001
User is online
Mail.app
0
08/15, 8:39pm, EDT
This is a big one:

(And the people who get credit must be pretty fast, because this was reported by zillions of people, myself included, before "official" release date. :)

---

Mail CVE-ID: CAN-2005-2512

Available for: Mac OS X v10.4.2, Mac OS X Server v10.4.2

Impact: Loss of privacy due to Mail loading remote images in HTML emails.

Description: When Mail.app is used to print or forward an HTML message, it will attempt to load remote images even if a user's preferences disallow it. As this network traffic is not expected, it may be considered a privacy leak. This update addresses the issue by having Mail.app only load remote images in HTML messages when the preferences allow it. This issue does not affect systems prior to Mac OS X v10.4. Credit to Brad Miller of CynicalPeak and John Pell of Foreseeable Solutions for reporting this issue.
Fresh-Faced Recruit
Joined Aug 2001
User is offline
Re: exploits and perspect
0
08/15, 10:32pm, EDT
34 exploits? Or vulnerabilities? There's a world of difference; most of what I see described in the notice are buffer-overflow "vulnerabilities", which are frequently only hypothetical, since actually exploiting a buffer overflow requires a bunch of other things to go right (for the bad guy). An "exploit" is a documented, reproducible way to take advantage of the vulnerability, and is a much more scary thing.

Yet no one seems to blink an eye when MS releases security patches for vulnerabilities and gets blasted for being insecure and full of holes, etc.

Apache CUPS LDAP Kerberos MySQL OpenSSL Squirrelmail X11 (XFree86/xorg) zlib

Are all services that Apple simply bundles and/or wraps a GUI around. Apple does not write or maintain code for these projects.


Hey, maybe Apple should spend some time working on these projects to make sure they aren't full of security holes before they decide to include it in their 'premier' OS, esp. one that everybody talks about being so secure...
Fresh-Faced Recruit
Joined Nov 2000
User is offline
Exploits/perspective
0
08/16, 9:30am, EDT
Yet no one seems to blink an eye when MS releases security patches for vulnerabilities and gets blasted for being insecure and full of holes, etc.

No argument here; people tend to jump on low-probability potential vulnerabilities with the same zeal as actual exploits, although MS does get properly hammered for blatant vulnerabilities that have let to real problems.
Fresh-Faced Recruit
Joined Aug 2004
User is offline
what was that movie about
0
10/07, 9:59pm, EDT
stopping a crime before it happens by using the think police?

This is so BS, compare exploits to exploits. So in the four years OSX has been out what's the score to windows now? 0 to 50,000+

go to the CERT search page and type in "exploit" http://search.cert.org/
Fresh-Faced Recruit
Joined Jan 2002
User is offline
Your Comments

In order to post comments: If you are a registered member, please login with your MacNN Forums username and password otherwise please uncheck the checkbox below.


Registered Member?
macnn forums login:

macnn forums password:

Not a member of the MacNN forums? Register now for free.

RSS Feeds

Have the latest content delivered to your desktop via RSS. Use the links below to get access to a specific blog, news, or reviews feed.



  MacNN -all

  MacNN Reviews

  MacNN Podcasts

  iPodNN

  Electronista

  Left Lane News
Want To Sell Your Laptop? Any Condition - receive Top Cash. Get an instant quote. Free shipping www.CashForLaptops.com
Buy from The Apple Store, iTunes.com, Amazon.com, TechDepot, OfficeDepot, Computers4Sure, or donate.