utilities/system updates
08/15/2005, 5:15pm, EDT
Monday, August 15th
Apple patches 34 exploits with latest security update
Apple today released Security Update 2005-007 for both client/server versions of Mac OS X 10.3 Panther (client/server) and Mac OS X 10.4 Tiger (client/server). Apple says the update delivers a number of security enhancements and is recommended for all Macintosh users. It includes updated components for Apache 2 (Server version only), AppKit (2), BlueTooth, CoreFoundation, cups printing service, Directory Services, HIToolBox, Kerberos authentication, Apple's loginwindow, several Mac OS X Server components, Mail.app email client, MySQL (Server-only), OpenSSL sysetm security layer, ping/traceroute networking tools, QuartzComposerScreenSaver, Security, Interface, Safari web browser, SquirrelMail mail server (Server only), X11 windowing system, WebKit (Tiger-only), Weblog Server (Tiger Server only) and zlib compression library.
Filed under: software
,
, 7
,
,
,
,
,

subscribe to comments
for this article
I think too many people are prone to use the words interchangeably, and thereby (as in this case) overstate the danger.
Buffer overflows are probably one of the most common programming errors made in C/C++; such vulnerabilities, when found, should be corrected, even if there is no known exploit. But please let's be careful in describing what Apple is fixing here.
Are all services that Apple simply bundles and/or wraps a GUI around. Apple does not write or maintain code for these projects.
(And the people who get credit must be pretty fast, because this was reported by zillions of people, myself included, before "official" release date. :)
---
Mail CVE-ID: CAN-2005-2512
Available for: Mac OS X v10.4.2, Mac OS X Server v10.4.2
Impact: Loss of privacy due to Mail loading remote images in HTML emails.
Description: When Mail.app is used to print or forward an HTML message, it will attempt to load remote images even if a user's preferences disallow it. As this network traffic is not expected, it may be considered a privacy leak. This update addresses the issue by having Mail.app only load remote images in HTML messages when the preferences allow it. This issue does not affect systems prior to Mac OS X v10.4. Credit to Brad Miller of CynicalPeak and John Pell of Foreseeable Solutions for reporting this issue.
Yet no one seems to blink an eye when MS releases security patches for vulnerabilities and gets blasted for being insecure and full of holes, etc.
Apache CUPS LDAP Kerberos MySQL OpenSSL Squirrelmail X11 (XFree86/xorg) zlib
Are all services that Apple simply bundles and/or wraps a GUI around. Apple does not write or maintain code for these projects.
Hey, maybe Apple should spend some time working on these projects to make sure they aren't full of security holes before they decide to include it in their 'premier' OS, esp. one that everybody talks about being so secure...
No argument here; people tend to jump on low-probability potential vulnerabilities with the same zeal as actual exploits, although MS does get properly hammered for blatant vulnerabilities that have let to real problems.
This is so BS, compare exploits to exploits. So in the four years OSX has been out what's the score to windows now? 0 to 50,000+
go to the CERT search page and type in "exploit" http://search.cert.org/