RSS RSS Twitter Twitter
apple news/media reports

11/14/2007, 5:20pm, EST

Wednesday, November 14th

Apple releases OS X 10.4.11, Panther updates

Apple today released Mac OS X 10.4.11, an update to its Tiger operating system that enhances stability, compatibility, and security while introducing Safari 3 -- the latest version of Apple's Web Browser. Mac OS X 10.4.11 adds RAW image decoding support for various digital cameras which include the Panasonic Lumix DMC-FZ50, Leica V-Lux 1, Olympus E-400, Olympus EVOLT E410, Olympus EVOLT E510, and Canon EOS 40D. The update also improves compatibility when using OpenType fonts in QuarkExpress, and enhances reliability when running VMWARE's Fusion virtualization software. The update requires Mac OS X 10.4 Tiger, and is recommended by Apple for all Tiger users.

Mac OS X 10.4.11 improves support for using Image Capture to import pictures taken with an iPhone, offers better syncing between iPhones and Yahoo! address books, and provides greater reliability when advertising an AFP sharepoint via Bonjour. The latest release of Tiger addresses issues related to copying files from a Mac OS 9 AFP sharepoint, port mapping when sharing a Mac's internet connection, and selecting two rows of album art within the iTunes artwork Screen Saver.

Users updating to the latest revision of Tiger can expect increased reliability when trying to authenticate to an AFP share using Kerberos, as well as better compatibility with third-party wireless wide-area network devices. Support for Microsoft Presenter Mouse 8000 is included in Mac OS X 10.4.11, as is updated Daylight Saving Time information for customers in Australia as wella s New Zealand and Indiana.

Tiger-oriented Macs now allow the use of special keys on aluminum Apple Keyboards to control Aperture slideshows, and the update addresses an issue where help content for some applications could display in English when using the computer in another Mac OS X language. Various issues with certain Apple Dashboard widgets like Unit Converter, Calculator, and Stocks are also addressed in Mac OS X 10.4.11.

Mac OS X 10.3 "Panther" security fixes

Offered alongside the latest release of Mac OS X Tiger is an update for Panther users who have not or cannot update to Tiger or Leopard. Apple's Security Update 2007-007 addresses issues with AppleRAID, bind, CoreFoundation, Flash Player Plug-in, and Foundation.

bzip2

A file name handling issue exists in bzgrep. By enticing a user into running bzgrep on a file with a maliciously crafted name, an attacker may trigger the issue which may lead to arbitrary code execution. This update addresses the issue through improved handling of file names.

CFNetwork

By enticing a user to follow a maliciously crafted FTP URI, an attacker can cause the user's FTP client to issue arbitrary FTP commands to any accessible FTP server, using the credentials of the user. This update addresses the issue by performing additional validation of FTP URIs.

CFNetwork

An HTTP response splitting vulnerability exists in CFNetwork. By sending a maliciously crafted HTTP response to a user's HTTP request, an attacker may alter the user's consecutive responses, which could lead to cross-site scripting. This update addresses the issue through improved parsing of HTTP responses. Credit to Steven Kramer of sprintteam.nl for reporting this issue.

CoreAudio

A design issue exists in the Java interface to CoreAudio. JDirect exposes an interface that may allow freeing arbitrary memory. By enticing a user to visit a web page containing a maliciously crafted Java applet, an attacker can trigger the issue which may lead to arbitrary code execution. This update addresses the issue by performing additional security checks in the Java interface to CoreAudio.

CoreAudio

An issue exists in the Java interface to CoreAudio, which may allow reading or writing out of the bounds of the allocated heap. By enticing a user to visit a web page containing a maliciously crafted Java applet, an attacker can trigger the issue which may lead to arbitrary code execution. This update addresses the issue by performing additional bounds checking.

CoreAudio

An issue exists in the Java interface to CoreAudio, which may allow instantiation or manipulation of objects outside the bounds of the allocated heap. By enticing a user to visit a web page containing a maliciously crafted Java applet, an attacker can trigger the issue which may lead to arbitrary code execution. This update addresses the issue by performing additional security checks in the Java interface to CoreAudio.

cscope

Cscope is updated to version 15.6 to address several vulnerabilities, the most serious of which are buffer overflow and insecure temporary file creation vulnerabilities. Further information is available via the Cscope web site at http://cscope.sourceforge.net/

gnuzip

A file name handling issue exists in zgrep. By enticing a user into running zgrep on a file with a maliciously crafted name, an attacker may trigger the issue which may lead to arbitrary code execution. This update addresses the issue by through improved file names handling.

iChat

A buffer overflow vulnerability exists in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) code used to create Port Mappings on home NAT gateways in iChat. By sending a maliciously crafted packet, an attacker on the local network can trigger the overflow which may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation when processing UPnP protocol packets in iChat.

Kerberos

Multiple vulnerabilities exists in the MIT Kerberos administration daemon (kadmind), which may lead to an unexpected application termination or arbitrary code execution with system privileges. Further information on the issue and the patch applied is available via the MIT Kerberos website at http://web.mit.edu/Kerberos/ Credit to the MIT Kerberos Team for reporting these issues, which were originally discovered by Wei Wang of McAfee Avert Labs.

mDNSResponder

A buffer overflow vulnerability exists in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) code used to create Port Mappings on home NAT gateways in the Mac OS X implementation of mDNSResponder. By sending a maliciously crafted packet, an attacker on the local network can trigger the overflow which may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by removing UPnP IGD support. This issue does not affect systems prior to Mac OS X 10.4.

PDFKit

An integer underflow exists in Preview's handling of PDF files. By enticing a user to open a maliciously crafted PDF file, an attacker may trigger the issue which may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation of PDF files. This issue does not affect systems prior to Mac OS X 10.4.

PHP

PHP is updated to version 4.4.7 to address several vulnerabilities. Further information is available via the PHP web site at http://www.php.net.

Quartz Composer

An uninitialized object pointer vulnerability exists in the handling of Quartz Composer files. By enticing a user to view a maliciously crafted Quartz Composer file, an attacker may trigger the issue which may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing proper initialization of object pointers. This issue does not affect systems prior to Mac OS X 10.4.

Samba

Multiple heap buffer overflows exist in the Samba daemon. By sending maliciously crafted MS-RPC requests, a remote attacker can trigger the overflow which may lead to arbitrary code execution. This update addresses the issue by performing additional validation of MS-RPC requests.

Samba

A command injection vulnerability exists in the Samba daemon. By sending maliciously crafted MS-RPC requests, a remote attacker can trigger the command injection. This update addresses the issue by performing additional validation of MS-RPC requests. This issue does not affect the default Samba configuration.

Samba

An issue exists in Samba when a server process drops its privileges. This could allow the quota enforcement to be bypassed, and the file system quota to be exceeded. This update addresses the issue by properly dropping privileges. Credit to Mike Matz of Wyomissing Area School District for reporting this issue.

SquirrelMail

SquirrelMail is updated to version 1.4.10 to address several vulnerabilities, the most serious of which is cross-site scripting triggered by viewing HTML mail. Further information is available via the SquirrelMail web site at http://www.SquirrelMail.org/

Tomcat

Tomcat is updated to version 4.1.36 to address several vulnerabilities, the most serious of which are cross-site scripting and information disclosure. Further information is available via the Tomcat site at http://tomcat.apache.org/ These issues do not affect systems prior to Mac OS X 10.4.

WebCore

Safari provides an "Enable Java" preference, which when unchecked should prevent the loading of Java applets. By default, Java applets are allowed to be loaded. Navigating to a maliciously crafted web page may allow a Java applet to be loaded without checking the preference. This update addresses the issue through a stricter check of the "Enable Java" preference. Credit to Rhys Kidd and Scott Wilde for reporting this issue.

WebCore

An issue exists in WebCore when parsing comments inside an HTML title element. This can allow an attacker to insert scripts into a web page on sites which allow the page owner to enter HTML, but not scripts. This update addresses the issue by correctly parsing comments in title elements.

WebCore

A design issue in WebCore allows a popup window to read the URL that is currently being viewed in the parent window. By enticing a user to visit a maliciously crafted web page, an attacker can trigger the issue, which may lead to the disclosure of information via the URL contents. This update addresses the issue through an improved cross-domain security check. Credit to Secunia Research for reporting this issue.

WebCore

In Safari, properties of certain global objects are not cleared when navigating to a new URL within the same window. By enticing a user to visit a maliciously crafted web page, an attacker may trigger the issue which may lead to cross-site scripting. This update addresses the issue by properly clearing global objects.

WebKit

The International Domain Name (IDN) support and Unicode fonts embedded in Safari could be used to create a URL which contains look-alike characters. These could be used in a malicious web site to direct the user to a spoofed site that visually appears to be a legitimate domain. This update addresses the issue by through an improved domain name validity check. Credit to Tomohito Yoshino of Business Architects Inc. for reporting this issue.

WebKit

Description: Heap buffer overflows exist in the Perl Compatible Regular Expressions (PCRE) library used by the JavaScript engine in Safari. By enticing a user to visit a maliciously crafted web page, an attacker may trigger the issue, which may lead to arbitrary code execution. This update addresses the issue by performing additional validation of JavaScript regular expressions. Credit to Charlie Miller and Jake Honoroff of Independent Security Evaluators for reporting these issues.


Filed under: Apple

, , 14comments, del.icio.us, slashdot, digg, buzz , Twitter



14 comments
Reader Reactions (Please use <i></i> for italic text)

subscribe to comments
for this article




Expand All   Global Settings
So...
1
11/14, 5:44pm, EST
does it fix the 10.4.10 airport problem MBP owners have been experiencing?
Fresh-Faced Recruit
Joined Aug 2001
User is offline
Panther eh?
1
11/14, 8:49pm, EST
Haven't seen an update to Panther in a while. . . I'm impressed.
Fresh-Faced Recruit
Joined Nov 2007
User is offline
some already patched
0
11/14, 9:16pm, EST
They already patched some of the items in this list in previous security updates. I guess they're re-listing everything since 10.4.10 to be complete.
Fresh-Faced Recruit
Joined Jan 2005
User is offline
Re: panther, eh
0
11/14, 9:58pm, EST
Panther's been updated generally with the same security patches as Tiger.

Although Apple has never officially stated for how long either Panther or Tiger will be supported with security fixes. Guess they don't want to give those annoying IT people any type of useful information.
Fresh-Faced Recruit
Joined Aug 2001
User is offline
nice fix
0
11/15, 12:01am, EST
"Various issues with certain Apple Dashboard widgets like Unit Converter, Calculator, and Stocks are also addressed in Mac OS X 10.4.11."

It addressed the issues so well that the Weather and the Stocks widgets don't work now - totally blank. Nice.
Fresh-Faced Recruit
Joined Jul 2006
User is offline
ARG!
0
11/15, 8:28am, EST
10.4.11 jacked everything up and my MB would no longer boot. I had to boot from the DVD and do an reinstall of the system. I haven't had to do that since Mac OS 9...
Grizzled Veteran
Joined Aug 2002
User is offline
re: arg!
0
11/15, 9:23am, EST
did you repair permissions first? ALWAYS repair permissions before doing an OS update.

Safari is now much more persnickety about XHTML docs; warning to webmonkeys out there!
Fresh-Faced Recruit
Joined Sep 2001
User is offline
Re: re: arg!
0
11/15, 10:33am, EST
>ALWAYS repair permissions before doing an OS update

Isn;t this an urban myth/old wives tale. Apple have never advocated this.
Permisssions
0
11/15, 11:12am, EST
[Isn;t this an urban myth/old wives tale. Apple have never advocated this.]

No. Just common sense. Bad permissions can lead to a corrupt installation which could cause more problems down the road or make the software inoperable.
Fresh-Faced Recruit
Joined Oct 2007
User is offline
re: old wives' tales
0
11/15, 11:32am, EST
urban legend? Huh? Repairing permissions is something that should be done weekly, anyway, unless you don't use your computer much. It fixes 90% of what's ailed my Mac in the past.
Fresh-Faced Recruit
Joined Sep 2001
User is offline
additional comments:..1..2..Next
Your Comments

In order to post comments: If you are a registered member, please login with your MacNN Forums username and password otherwise please uncheck the checkbox below.


Registered Member?
macnn forums login:

macnn forums password:

Not a member of the MacNN forums? Register now for free.

RSS Feeds

Have the latest content delivered to your desktop via RSS. Use the links below to get access to a specific blog, news, or reviews feed.



  MacNN -all

  MacNN Reviews

  MacNN Podcasts

  iPodNN

  Electronista

  Left Lane News
Want To Sell Your Laptop? Any Condition - receive Top Cash. Get an instant quote. Free shipping www.CashForLaptops.com

Internet Marketing School - 100% Online: Master SEO, SEM, E Commerce, Media & More with a U of San Francisco Certificate.

Buy from The Apple Store, iTunes.com, Amazon.com, TechDepot, OfficeDepot, Computers4Sure, or donate.