05/01/2007, 4:30pm, EDT
Tuesday, May 1st
Apple fixes security update bug, flaw
Apple notes that the Security Update 2007-004 applied an incorrect ftp configuration file for Mac OS X Server v10.4.9 systems.
"Users with ftp access, who would normally be restricted to certain directories, may be able to access directories outside the normal scope. This update addresses the issue by restoring the correct version of the ftp configuration file. This issue only affects Mac OS X Server v10.4.9 with Security Update 2007-004."
Mac OS X 10.4.9 (client) and Mac OS X Server 10.3.9 systems that have already installed Security Update 2007-004 are not affected and the Software Update utility will not display Security Update 2007-004 1.1 for these systems, the company said in its documentation.
The update, however, does not contain fixes for two older zero-day QuickTime flaws, which could allow attackers to make QuickTime stop responding or execute arbitrary code as the user. Apple also did not address the Safari flaw that allowed researchers to hack a MacBook Pro at the CanSecWest security conference.
Update: Apple on Tuesday also released QuickTime 7.1.6 to address a critical zero-day flaw in QuickTime for Java.
Filed under: software
,
, 3
,
,
,
,
,

subscribe to comments
for this article
http://thunkdifferent.com