View this article at: http://www.macnn.com/articles/05/02/22/security.update.2005.002/
Tuesday, Feb 22, 2005 4:40pm
Apple releases Security Update 2005-002
Apple has released Security Update 2005-002 via the Software Update utility in Mac OS X. The update delivers a number of security enhancements and is recommended for all Mac OS X users. The update includes the following components: Java Web Start, JavaPluginCocoa.bundle, JavaScriptCore, and Core Java classes. Apple says the update addresses an issue where an untrusted applet could gain elevated privileges and potentially execute arbitrary code: " A vulnerability in the Java Plug-in may allow an untrusted applet to escalate privileges, through JavaScript calling into Java code, including reading and writing files with the privileges of the user running the applet. Releases prior to Java 1.4.2 on Mac OS X are not affected by this vulnerability."