On TV.com: Julie is HOT (and so is TV in a FLASH)
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Mar 14, 2006 12:15:00 AM

Apple Computer on Monday released the second set of Mac OS X security fixes in two weeks.

Security Update 2006-002 corrects problems caused by the company's previous patch and fixes newly discovered security flaws, some of which could let an attacker run code on a computer with the same privileges as the user, the company said on its Web site.

"This Security Update includes some upgrades to our download validation mechanism and strengthens it," Bud Tribble, Apple's vice president of software technology, told CNET News.com. "We reduced the number of false positives it gives."

Earlier this month Apple released a security update for its operating system to plug 20 holes. That update added download validation to the Safari Web browser, Apple Mail client and iChat instant-messaging tool. The function warns people that a download could be malicious when they click on the link.

However, download validation has been sounding the alarm on harmless files. "Security Update 2006-001 could cause the user to be warned when provided with certain safe file types, such as Word documents, and folders containing custom icons," Apple said in its security alert. The new update fixes that problem, the company said.

Additionally, Apple's previous update didn't entirely fix the problem. Malicious files could still run without any user action, Apple said. "This update provides additional checks to identify variations of the malicious file types addressed in Security Update 2006-001 so that they are not automatically opened," according to the alert.

The earlier patch also introduced errors with the PHP scripted programming language and "rsync" file transfer utility, Apple said. The PHP issue may prevent SquirrelMail from running and the rsync "--delete" command may not work, the company said. That is now corrected.

The new security update also fixes a pair of newly discovered flaws. One bug is a buffer overflow error in Apple Mail that could be triggered by enticing a user to double click on an e-mail attachment, Apple said. The bug could let an attacker run code in the context of the user, the company said.

The second flaw is related to how Mac OS X handles documents that contain JavaScript. An attacker could craft a file and host it on a remote Web site that would bypass certain access restrictions on a Mac when opened, according to Apple's advisory.

Security-monitoring company Secunia rates Apple's new fix "extremely critical," its highest-risk rating that's not often awarded.

While Apple urges its users to install the patches, there is no immediate risk of attack, Tribble said. "None of these issues are things where there are exploits in the wild," he said. "In a way you can say these are pre-emptive fixes to prevent problems from arising."

The new patch comes after weeks of scrutiny of the safety of OS X, prompted by the discovery of two worms and the disclosure of a serious vulnerability. Security experts also were questioning the effectiveness of Apple's latest patch, suggesting the company should add protection at a deeper level in the system.

Security Update 2006-002 can be downloaded and installed via the Software Update feature in Mac OS X or from Apple Downloads.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 128 Talkback(s)
QuantumTunnelRat, because you cannot think as well as humans -I?ll help you
The point was that according to scientific methods of processing/analyzing information - Mac-fanatics CANNOT prove that their Macs are invulnerable.

But due to your extremely low intelli... (Read the rest)
Posted by: Vily Clay Posted on: 03/16/06 You are currently: a Guest | | Terms of Use
Are they patching a patch?  toadlife | 03/13/06
Go figure!  NonZealot | 03/14/06
...  crampy20 | 03/14/06
neither  doh123 | 03/14/06
The latter  tic swayback | 03/14/06
How can you be sure that ...  Vily Clay | 03/13/06
Well has ANYONE....anyone at all reported some form of damage from Malware?  Laff | 03/13/06
To answer your question . . .  999ad@... | 03/14/06
That's the thing..  tic swayback | 03/14/06
ZDNet forum-version of Mac-loyalty = if your Mac troubles you ? ...  Vily Clay | 03/14/06
The crux is "IF" it troubles you.....:) Is that your problem Vily?  Laff | 03/14/06
Why bother?  Rick_K | 03/14/06
It means you have no brains to talk with valid arguments/facts/logic. (NT)  Vily Clay | 03/14/06
Good point Vily  tic swayback | 03/14/06
Then what you are doing here if "ZDNet is a terrible place"? (NT)  Vily Clay | 03/14/06
I come here for entertainment  tic swayback | 03/14/06
Logically it means: you are not welcome anywhere, ...  Vily Clay | 03/14/06
Corrections  tic swayback | 03/14/06
Thanks for your explanation - why you love Britney Spears and the like ...  Vily Clay | 03/14/06
One more correction  tic swayback | 03/14/06
Tic,your statement? ?I'm pretty much always drunk? explains everything (NT)  Vily Clay | 03/14/06
Tell that to my wife (nt)  tic swayback | 03/14/06
Advise: Tic, if she doesn?t understand your Apple English ? drop Apple (NT)  Vily Clay | 03/14/06
Don't worry  tic swayback | 03/15/06
... and your wife? (NT)  Vily Clay | 03/15/06
She's more of a gin drinker....  tic swayback | 03/15/06
It?s obvious that a few martinis before she can stand to look at ZDNet ...  Vily Clay | 03/15/06
did Steve hit your dog with his car?  woot! | 03/14/06
You shouldn?t read truth about Mac ? it can hurt your illusions. (NT)  Vily Clay | 03/14/06
Truth....No one has been hurt by malware useing OSX.  Laff | 03/14/06
Can you prove it? No way. It means you trust your Illusions.  Vily Clay | 03/14/06
We still use Macs on both 8.6 (Rare granted but some)  Laff | 03/14/06
Laff, why should people trust your illusions about Mac OS 8.6? (NT)  Vily Clay | 03/14/06
Not asking for trust......just reporting our situation.  Laff | 03/14/06
Do you remember that you reported the situation only with Mac OS 9.2.2?(NT)  Vily Clay | 03/14/06
hold on there sparky  woot! | 03/14/06
Can you tell me the reason why did you write this message? (NT)  Vily Clay | 03/14/06
just wanted to point out...  woot! | 03/15/06
QuantumTunnelRat, according to common sense - you have no reasons to talk.  Vily Clay | 03/15/06
Vily, Vily, vily  woot! | 03/16/06
Finally you agreed you?ve no logical arguments/facts/etc=no reasons to talk  Vily Clay | 03/16/06
sure, whatever  woot! | 03/16/06
QuantumTunnelRat, because you cannot think as well as humans -I?ll help you  Vily Clay | 03/16/06
but you can read all the issues posted  woot! | 03/14/06
Please, what's your version - Why Apple killed feedbacks?Too negative? (NT)  Vily Clay | 03/14/06
Any answer I give  woot! | 03/14/06
Steve Jobs and the Woz gave him a "swirly" in HS...:)  Laff | 03/14/06
A swirly? naw...  woot! | 03/14/06
So there is something to hide from Mac users, but you don?t care what? (NT)  Vily Clay | 03/14/06
unfortunately  woot! | 03/14/06
It?s interesting ? since when telling truth about Apple is spamming? (NT)  Vily Clay | 03/14/06
COOL!!!!! Quick to respond and if at first you don't succeed  Laff | 03/13/06
Thank you OSX...  NonZealot | 03/14/06
Toads and Shares, bad mix.  crampy20 | 03/14/06
What type of Mac machines do you run?  j.m.galvin | 03/14/06
Ooooo, I'm going to need links for this one!!!  NonZealot | 03/14/06
Yes thank you OSX....:)  Laff | 03/14/06
I'm all ears!  NonZealot | 03/14/06
This is another one of thos Prove God/Disprove God questions.  Laff | 03/14/06
Interesting argument coming from a Pagan!  NonZealot | 03/14/06
Granted it won't spread like a Windows viri/malware but  Laff | 03/14/06
Odd!  mbrierley | 03/15/06
Finally! THE TRUTH!  ajole | 03/14/06
Perhaps  tic swayback | 03/14/06
not a high marketshare  doh123 | 03/14/06
Ah, I understand  NonZealot | 03/14/06
Not quite that skewed and you know that Non...:)  Laff | 03/14/06
Marketshare numbers are deceiving  tic swayback | 03/14/06
Same holds true of OSX though  NonZealot | 03/14/06
yep  doh123 | 03/14/06
Try harder  NonZealot | 03/14/06
my point  doh123 | 03/14/06
Do the math  tic swayback | 03/14/06
Yes, do the math  NonZealot | 03/14/06
Mathemagical Land  tic swayback | 03/14/06
Profit from malware  NonZealot | 03/14/06
Good points  tic swayback | 03/14/06
Not sure it's the same though  tic swayback | 03/14/06
And then factor in Dual boot!  ajole | 03/14/06
true, you should use common sense  cgrecu | 03/14/06
Now let's expand on that  Rick_K | 03/14/06
Now lets expand on that again  NonZealot | 03/14/06
Doesn't that prove the point?  tic swayback | 03/14/06
Logic must not be your strong suit.  Rick_K | 03/14/06
Aww, pumpkin, logic is fun!  NonZealot | 03/14/06
And yet more painful logic  NonZealot | 03/14/06
Aww Rick, run out of real arguments?  NonZealot | 03/14/06
NZ--again, you're proving my point  tic swayback | 03/14/06
are you sure?  Rick_K | 03/14/06
tic: lousy? I guess you are right  NonZealot | 03/14/06
Yes Rick, I'm sure. Are you?  NonZealot | 03/14/06
NZ Where's your data?  tic swayback | 03/14/06
Also  tic swayback | 03/14/06
yeah...  doh123 | 03/14/06
Then care to retract this?  NonZealot | 03/14/06
exactly as you quoted...  doh123 | 03/14/06
Hehe  NonZealot | 03/14/06
nope  doh123 | 03/14/06
HUUHHNNN???  ajole | 03/14/06
Define your terms  tic swayback | 03/14/06
I do agree.  ajole | 03/14/06
i meant...  doh123 | 03/14/06
Nice nonsequitor  woot! | 03/14/06
Ooooo, I'm going to need links for this one!!!  NonZealot | 03/14/06
Disagree with your assertion  woot! | 03/14/06
Last time I'll respond to your off-topic post  NonZealot | 03/14/06
McDonalds vs 5-Star Eatery of your choice?  Laff | 03/14/06
Why use logic?  Rick_K | 03/14/06
I agree Laff  NonZealot | 03/14/06
another dumb argument ...  cgrecu | 03/14/06
Dude...everything is relative to it's given situation.  Laff | 03/14/06
Yeah, cars again!  ajole | 03/14/06
Are you really that dense?  Rick_K | 03/14/06
Again your logic applies to OSX too  NonZealot | 03/14/06
My point  Rick_K | 03/14/06
What, no comback?  Rick_K | 03/14/06
Oops, not up on ZDNet vulnerabilities, are you?  NonZealot | 03/14/06
Oops, not up on ZDNet vulnerabilities  Rick_K | 03/14/06
RE: Rick_K  ShadeTree | 03/15/06
The problem is not the server...  tic swayback | 03/15/06
stupid logic ... sorry to say  cgrecu | 03/14/06
Reflecting sales, not user base  tic swayback | 03/14/06
Tic...  Rick_K | 03/14/06
Ok, for the slow minded  Rick_K | 03/14/06
OK, for the Mac minded...  ajole | 03/14/06
Think again (also for NonZealot)  Rick_K | 03/15/06
its a common license  doh123 | 03/14/06
Bottom line  woot! | 03/14/06

What do you think?

advertisement
advertisement
Click Here

White Papers, Webcasts, and Downloads