troubleshooting/tutorials/security
03/13/2006, 4:35pm, EST
Monday, March 13th
Apple releases another security update
Apple today released yet another security update that improves on its previous attempt to address the Mac OS X Zero Day exploit in its Safari browser and bundled email application (Mail.app). Apple's Security Update 2006-001, released last week, addressed an issue where Safari could automatically open a file which appears to be a safe file type, such as an image or movie, but is actually an application. The new Security Update 2006-002 update provides additional checks to identify variations of the malicious file types addressed in Security Update 2006-001 so that they are not automatically opened, according to Apple. This issue does not affect systems prior to Mac OS X v10.4. The update also provides fixes for a JavaScript flaw in CoreTypes as well as provides bug fixes in the Apache PHP module, download validation, and rysnc introduced by the previous security update. Earlier today, we noted new security flaws in iTunes and QuickTime, which have yet to be addressed. The update is available via the Software Update or the web for both Mac OS X 10.4 Tiger (PPC Client/Server, Intel Client Only) and Mac OS X 10.3 Panther client and Server versions.
Filed under: troubleshooting
,
, 9
,
,
,
,
,

subscribe to comments
for this article
Be sure to do a "repair permissions" in Disk Utility after a system update. I haven't done it yet myself, but I'm doing it in a moment...
http://www.scarydevil.com/~peter/io/apple3.html
For seven years our primary "antivirus" was "don't use internet explorer or outlook" (the applications that are the poster-boys for this kind of social engineering) and "learn from your mistakes".
I occasionally had to go and fix someone's PC because they'd downloaded a file to the desktop and then opened it and it turned out to be a bad-un. I never had to do it twice with anyone. Even the 'cup-holder' level users learned to check what downloaded files and attachments were trying to run as instead of just double-clicking them.