toggle

AAPL Stock: 509.46 ( + 6.86 )

Apple fixes Safari, other exploits

updated 05:30 pm EST, Wed March 1, 2006

Apple Security Update


Apple today released Security Update 2006-001 for both Mac OS X Panther and Mac OS X Tiger, which is recommended for all users and improves Safari by fixng four different security issues, including the 'extremely critical' Mac OS X zero-day exploit and three other exploits that could enable arbitrary code execution by a malicious user. It also fixes 13 other bugs in the following components: apache_mod_php, automount, Bom, Directory Services, iChat, IPSec, LaunchServices, LibSystem, loginwindow, Mail, rsync, and Syndication. Apple also said that its AES-128 encrypted FileVault disk images are now created with more restrictive operating system permissions and that improved iChat security by using Download Validation to warn of unknown or unsafe file types during file transfers--in part to protect against the recently reported Leap.A worm.

The update fixes multiple security issues in PHP, the popular web programming language included with the Apache webserver installation. The latest version is installed, but turned off in default installations of Mac OS X. The an automount issue that could cause the systems to become unresponsive, or possibly allow arbitrary code delivered from the file servers to run on the target system.

Apple also notes that the update more securely stores passwords: "The passwd program is vulnerable to temporary file attacks. This could lead to privilege elevation. This update addresses the issue by anticipating a hostile environment and by creating temporary files securely."


by MacNN Staff

(9)

TAGS :

 software
toggle

Comments

  1. e:leaf

    Fresh-Faced Recruit

    Joined: Mar 2006

    0

    It's nice to see . . .

    Apple jump on these security issues so quickly. As Mac users, security is something which we have not had to worry all that much about, and then all of a sudden, last week saw 3 new potential exploits.

    Granted none of them could cause harm in their current forms, but the concepts they were trying to display were solid enough to warrant a quick response.

    And a quick response we got.

  1. e2Sync

    Fresh-Faced Recruit

    Joined: Feb 2005

    0

    Not so fast...

    These issues have been around a long time and Apple has been openly criticized for taking so long to fix them. This criticism increased last week, probably spurring some action from Apple. Finally. So sorry, but your post is the total opposite of what's been happening. It seems Apple only fixes thing when people jump up and down about them.

  1. MacnTX

    Fresh-Faced Recruit

    Joined: Apr 2004

    0

    Consider The Alternative

    Whatever. At least Apple responds with an update BEFORE it's users are negatively impacted by threats. Too bad we can't say the same for that other company that makes a major OS used by millions of people.

  1. Terrin

    Fresh-Faced Recruit

    Joined: Jan 2006

    0

    Get Your facts Straight

    Two Three weeks ago, some "security" company exposed two supposed major possible security exploits in Apple's OS. Two Three weeks later Apple responded by fixing the exploits. That is pretty good response time.

    It is also fair to point out, these were possible exploits, not actual exploits.

  1. ibugv4

    Fresh-Faced Recruit

    Joined: Jun 2003

    0

    umm...

    All of these "exploits" needed Admin access. In a professional networking environment, the end users are NOT admins and cannot be affected by most of these eploits. End users do not run PHP, as an example. Apple didn't see them as critical needs till some idiot decided to blast them for it. So, KUDOS APPLE for making them shut up. Now get back to making the OS LEAN and not BLOATED!

  1. paladin2664

    Fresh-Faced Recruit

    Joined: Mar 2006

    0

    well now my G5 is secure.

    The security of the dead... did the automatic update, and it killed my primary HD. Havn't narrowed down exactly whats wrong but after the restart the partition OSX10.4.5 was on became unmountable as did a backup OS partition I had on that drive. My other HD is ok but the system can't get past trying to mount the drives. Option lets me select a CD boot but I am really hosed. - Will update if I learn more.

  1. testudo

    Fresh-Faced Recruit

    Joined: Aug 2001

    0

    Re: consider the alternat

    Whatever. At least Apple responds with an update BEFORE it's users are negatively impacted by threats. Too bad we can't say the same for that other company that makes a major OS used by millions of people.

    Most windows holes re patched prior to their announcement and info, let alone before exploits are released. The problem with windows is that, with so many users, there's a whole segment that never runs the update feature.

    I'm sure OS X has the same percentage of non-updaters. Esp if they are NOT admins, where they'll never know there's an update until the admin logs in.

    Oh, and most macs are NOT used in professional networking environments, and most users are, in fact, admins (apple's default setup - hey, just like Windows!). Users would have to know what they're doing, read non-included manuals and on-line help to just know that they might want to consider setting up a limited account.

  1. paladin2664

    Fresh-Faced Recruit

    Joined: Mar 2006

    0

    Update on Update Problems

    I just spoke with 2 inidividuals who have had similar HardDrive problems directly after the patch. in one case same as mine a total loss of directory structure, in the other directory failures and constant pinwheel and crashing of applications.

  1. TomR

    Dedicated MacNNer

    Joined: Aug 2000

    0

    At least they...

    ...don't take forever to patch their OS unlike SOME companies, coughMICROSOFTcough....

    I had no issues doing the update on this Mac mini.

    Tom

Login Here

Not a member of the MacNN forums? Register now for free.

 
close
Photo
toggle

Network Headlines

toggle

Most Popular

10 Most Read

Recent Reviews

Logitech Cube

The world of mice could often be described charitably as stagnant: it's an endless sea of ergonomic shapes that assume you're sitting ...

NewerTech and Targus USB Hubs For Gifts

A useful holiday present to resolve an ongoing frustration is a multi-port hub. Whether as a stocking stuffer, Chanukah present, or an ...

X-Rite ColorMunki Photo

Color calibration is the art of tweaking your monitor so that the colors represented on screen better match real life and your printer ...

toggle

Most Commented

10 Most Discussed