On UrbanBaby: Working Mother Confession
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Mar 14, 2007 12:16:00 AM

Apple on Tuesday issued a security update for its Mac OS X to plug 45 security holes, including several zero-day vulnerabilities.

The megapatch is the seventh Apple security patch release in three months. It deals with vulnerabilities in Apple's own software, as well as third-party components such as Adobe Systems' Flash Player, OpenSSH and MySQL. Sixteen of the vulnerabilities addressed by the update were previously released as part of two high-profile bug-hunting campaigns.

The vulnerabilities pose varying risks to Macs. Several of the flaws could be exploited to gain full control over a Mac running the vulnerable component, according to Apple's advisory. Other holes are limited and could only be exploited to crash a Mac or used by somebody who already has access to a machine to elevate privileges, for example.

One focus of the patch is to fix eight vulnerabilities in the way Mac OS X handles disk images, files that when opened appear as a drive within the Macintosh Finder. Mounting a malicious image may lead to an error and could provide a means for an attacker to breach a Mac, Apple said.

Tuesday's update deals with nine vulnerabilities released as part of the Month of Apple Bugs in January and seven bugs disclosed in the Month of Kernel Bugs in November. In earlier fix releases, Apple fixed several flaws identified during the projects.

While several of the vulnerabilities repaired by Apple's updates were previously known, it doesn't appear that any attacks that exploited the flaws actually occurred.

In addition to the Mac OS X patch, Apple issued a second update on Tuesday to fix a security bug in iPhoto that could expose Mac users to a serious attack. An attacker could craft a malicious "photocast" which, when opened, could compromise a Mac, Apple said in its alert. The Photocasts feature allows people to share pictures in iPhoto.

Tuesday's two releases bring Apple's total patch count for the year to seven. Microsoft, meanwhile, on Tuesday skipped its monthly patch day. However, it released a dozen security bulletins with fixes for 20 vulnerabilities in February and four bulletins with fixes for 10 bugs in January.

The Apple patch can be downloaded and installed via the Software Update feature in Mac OS X, or from Apple Downloads.

  • Talkback
  • Most Recent of 115 Talkback(s)
And, by user opinon or momentum, more ppl use Windows
it just a fact. Maybe they don't enjoy using it, or maybe they do, but numbers show that again and again, for love or hate of the security model and patches, they return. There' no comparison.... (Read the rest)
Posted by: Boot_Agnostic Posted on: 03/21/07 You are currently: Logged In | Log out
Apple megapatch plugs 45 security holes Loverock Davidson   | 03/13/07
And? jbravo556   | 03/13/07
And! Loverock Davidson   | 03/13/07
Get a Mac and be done with it mlindl   | 03/20/07
I'll stick with Windows NonZealot   | 03/14/07
how do you arrive at the figure 4500? galileon   | 03/14/07
OS9 had thirty-something viruses, trojans, etc. MacGeek2121   | 03/14/07
Is that actually true? John Zern   | 03/14/07
The worst virus is the wetware running the mouse ajole   | 03/14/07
*with* anti-virus NoMSfan   | 03/14/07
they need Virus Definitions MacGeek2121   | 03/14/07
And I wouldn't trade the freedoms xuniL_z   | 03/14/07
I hope that was in jest doh123   | 03/15/07
Vast Freedoms... Jkirk3279   | 03/15/07
98.7% will do A_Selby   | 03/14/07
I'm sure if anyone ever discovered a real virus on Mac OSX MacGeek2121   | 03/14/07
But how about this John Zern   | 03/14/07
Oh my God! cashaww   | 03/14/07
You'll stick with illogic John Sawyer   | 03/15/07
The Fact-Free zone continues mlindl   | 03/20/07
Windows is a victim of its own success A_Selby   | 03/14/07
Installed XP the other day... jasonp@...   | 03/14/07
That's exactly right (NT) Badgered   | 03/14/07
Yes. Spend your money where your ethics is. Dont support what you dont like nomorems   | 03/14/07
Installed XP P,Mac Tiger,SuSe,Debian seapalmer   | 03/14/07
Couldn't have put it better... A_Selby   | 03/14/07
There is... cashaww   | 03/14/07
Lovey's back in first place jorjitop   | 03/14/07
You think not, nor can you count. deleweye   | 03/20/07
Nice FUD Rick_K   | 03/13/07
ZDNet is a NBM group? toadlife   | 03/13/07
Is it a service pack? PB_z   | 03/13/07
It's like xp sp2 Rick_K   | 03/14/07
300 MB XPSP2 download is for the standalone install PB_z   | 03/14/07
OSX has a lot of service packs!! NonZealot   | 03/14/07
At least Apple is *doing* something fde101   | 03/14/07
Just ignore WinZealot Rick_K   | 03/14/07
In case it slipped your mind zkiwi   | 03/14/07
Happy NoMSfan   | 03/14/07
Actually, Microsoft slipped a month 3D0G   | 03/14/07
Huh? NonZealot   | 03/14/07
And.... zkiwi   | 03/14/07
what do you care? snoople   | 03/14/07
Huh??? John Sawyer   | 03/15/07
then buy a service pack.... JoeMama_z   | 03/14/07
You caught a tiger by the tale their Boot_Agnostic   | 03/21/07
Oh, and in case you can't read zkiwi   | 03/14/07
Patching is good! Negative spin on patching is bad. MacGeek2121   | 03/14/07
Windows is not a disaster A_Selby   | 03/14/07
Here is my.... cashaww   | 03/14/07
Agree with you Boot_Agnostic   | 03/15/07
Tell us your personal experience NoMSfan   | 03/14/07
Simple question frgough   | 03/14/07
This coming from the person who doesn't even know what the word BUILD means Scrat   | 03/14/07
You already know frgough   | 03/14/07
What the hell! cashaww   | 03/14/07
Simple answer NoMSfan   | 03/14/07
Honesty frgough   | 03/14/07
"Honesty you it is bringing the first step towards knowledge"? A_Selby   | 03/14/07
I am lost. cashaww   | 03/14/07
It's a simple question, if phrased correctly Badgered   | 03/14/07
Sorry frgough   | 03/14/07
Not really Badgered   | 03/14/07
Houses and patches ITguy5678   | 03/14/07
Which simply shows the "personal experience" question... rx7racer   | 03/14/07
Now that's a good response. A_Selby   | 03/14/07
Exploits DO exist for OSX NonZealot   | 03/14/07
You run Linux??? zkiwi   | 03/14/07
zkiwi: OSX is BSD? NonZealot   | 03/15/07
re: Which simply shows the "personal experience" question... Badgered   | 03/15/07
So... zkiwi   | 03/16/07
This is cashaww   | 03/14/07
A poll of one is meaningless John Sawyer   | 03/16/07
A poll of one is an Opinion Badgered   | 03/16/07
I have never had any malware problems on my Mac. MacGeek2121   | 03/14/07
Is that what macinsquash users are calling it? Rock_Built@...   | 03/14/07
I'm sorry, but... msalzberg   | 03/14/07
Sorry! Rock_Built@...   | 03/15/07
Fanboy A_Selby   | 03/14/07
Oh? ITguy5678   | 03/14/07
Consider everything... smdunn   | 03/15/07
How about facts? ITguy5678   | 03/15/07
How about facts? ITguy5678   | 03/15/07
out of curiosity Badgered   | 03/16/07
Error on server ITguy5678   | 03/19/07
How about facts? ITguy5678   | 03/15/07
How about facts? ITguy5678   | 03/15/07
get a clue kkimball21@...   | 03/20/07
And, by user opinon or momentum, more ppl use Windows Boot_Agnostic   | 03/21/07
45 is still 45 Boot_Agnostic   | 03/14/07
wow Badgered   | 03/14/07
Well said NoMSfan   | 03/14/07
LOL! RocketEater   | 03/14/07
Actually there is NoMSfan   | 03/14/07
Don't forget frgough   | 03/14/07
to be honest Badgered   | 03/14/07
Amazing? tic swayback   | 03/14/07
So now you are back to xuniL_z   | 03/14/07
Huh? tic swayback   | 03/15/07
Now hopefully mac users will apply the update... JoeMama_z   | 03/14/07
Hahaha! xxn1927   | 03/14/07
Hahaha hahaha tic swayback   | 03/14/07
mac-patch... bgonetoo   | 03/15/07
Another "NonZealot" oddity John Sawyer   | 03/16/07
just one question Badgered   | 03/16/07
And the answer John Sawyer   | 03/16/07
It is not a given. It is an assumption. Badgered   | 03/16/07
"NonZealot" has one good point John Sawyer   | 03/16/07
No exploits for Apple? derekgore   | 03/16/07
Exploits vs propagation John Sawyer   | 03/16/07
But in those 5 years John Zern   | 03/18/07
New code means new bugs John Sawyer   | 03/19/07
Not all OSX users need it... alieninvader@...   | 03/20/07
Name the successful exploits for OSX mlindl   | 03/20/07
here the_fiddler_on_the_roof   | 03/20/07

What do you think?

advertisement
advertisement

Fusion

advertisement
Click Here