utilities/system updates

05/01/2007, 4:30pm, EDT

Tuesday, May 1st

Apple fixes security update bug, flaw

Apple today released a revised security update to fix a two bugs introduced with last week's update from the company, but did not address two important zero-day QuickTime flaws or a Safari flaw that was used to hack a MacBook. Security Update 2007-004 v1.1 (PPC version), for Mac OS X 10.3 Panther and for Mac OS X 10.4 Server systems, includes the contents of Security Update 2007-004 (released in mid-April) but also includes two crucial fixes for issues introduced by the update. Apple says it resolves a wake-after-sleep issue involving AirPort connections on Mac OS X 10.3.9 installed systems that was introduced in last week's security update. The latest update also fixes a newly introduced security issue that enables users with ftp access to navigate to directories outside the normal scope.

Apple notes that the Security Update 2007-004 applied an incorrect ftp configuration file for Mac OS X Server v10.4.9 systems.

"Users with ftp access, who would normally be restricted to certain directories, may be able to access directories outside the normal scope. This update addresses the issue by restoring the correct version of the ftp configuration file. This issue only affects Mac OS X Server v10.4.9 with Security Update 2007-004."

Mac OS X 10.4.9 (client) and Mac OS X Server 10.3.9 systems that have already installed Security Update 2007-004 are not affected and the Software Update utility will not display Security Update 2007-004 1.1 for these systems, the company said in its documentation.

The update, however, does not contain fixes for two older zero-day QuickTime flaws, which could allow attackers to make QuickTime stop responding or execute arbitrary code as the user. Apple also did not address the Safari flaw that allowed researchers to hack a MacBook Pro at the CanSecWest security conference.

Update: Apple on Tuesday also released QuickTime 7.1.6 to address a critical zero-day flaw in QuickTime for Java.


Filed under: software

, , 3comments, del.icio.us, slashdot, digg, buzz


3 comments
Reader Reactions (Please use <i></i> for italic text)

subscribe to comments
for this article




Expand All   Global Settings
Quick fix
0
05/01, 5:13pm, EDT
This is a good sign. Apple usually takes awhile to fix a flaw. That macbook hack (that works on windows and likely linux too) just happened. So, i'm glad to hear of this report and am updating the Cupertino 45.1 mb Quicktime update as i write.

http://thunkdifferent.com
Fresh-Faced Recruit
Joined Apr 2007
User is offline
re: quick fix
0
05/01, 6:12pm, EDT
The article says that the update does *not* address the recently Safari-based hack.
Fresh-Faced Recruit
Joined Apr 2007
User is offline
re: quick fix
0
05/02, 1:45am, EDT
But the accompanying QT update DOES fix the issue. (For both Mac and Windows.)
Senior User
Joined Dec 2000
User is offline
Your Comments

In order to post comments: If you are a registered member, please login with your MacNN Forums username and password otherwise please uncheck the checkbox below.


Registered Member?
macnn forums login:

macnn forums password:

Not a member of the MacNN forums? Register now for free.

RSS Feeds

Have the latest content delivered to your desktop via RSS. Use the links below to get access to a specific blog, news, or reviews feed.



  MacNN -all

  MacNN Reviews

  MacNN Podcasts

  iPodNN

  Electronista

  Left Lane News
Want To Sell Your Laptop? Any Condition - receive Top Cash. Get an instant quote. Free shipping www.CashForLaptops.com
Buy from The Apple Store, iTunes.com, Amazon.com, TechDepot, OfficeDepot, Computers4Sure, or donate.