On TechRepublic: Why Linux will triumph over Windows
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Mar 14, 2007 12:16:00 AM

Apple on Tuesday issued a security update for its Mac OS X to plug 45 security holes, including several zero-day vulnerabilities.

The megapatch is the seventh Apple security patch release in three months. It deals with vulnerabilities in Apple's own software, as well as third-party components such as Adobe Systems' Flash Player, OpenSSH and MySQL. Sixteen of the vulnerabilities addressed by the update were previously released as part of two high-profile bug-hunting campaigns.

The vulnerabilities pose varying risks to Macs. Several of the flaws could be exploited to gain full control over a Mac running the vulnerable component, according to Apple's advisory. Other holes are limited and could only be exploited to crash a Mac or used by somebody who already has access to a machine to elevate privileges, for example.

One focus of the patch is to fix eight vulnerabilities in the way Mac OS X handles disk images, files that when opened appear as a drive within the Macintosh Finder. Mounting a malicious image may lead to an error and could provide a means for an attacker to breach a Mac, Apple said.

Tuesday's update deals with nine vulnerabilities released as part of the Month of Apple Bugs in January and seven bugs disclosed in the Month of Kernel Bugs in November. In earlier fix releases, Apple fixed several flaws identified during the projects.

While several of the vulnerabilities repaired by Apple's updates were previously known, it doesn't appear that any attacks that exploited the flaws actually occurred.

In addition to the Mac OS X patch, Apple issued a second update on Tuesday to fix a security bug in iPhoto that could expose Mac users to a serious attack. An attacker could craft a malicious "photocast" which, when opened, could compromise a Mac, Apple said in its alert. The Photocasts feature allows people to share pictures in iPhoto.

Tuesday's two releases bring Apple's total patch count for the year to seven. Microsoft, meanwhile, on Tuesday skipped its monthly patch day. However, it released a dozen security bulletins with fixes for 20 vulnerabilities in February and four bulletins with fixes for 10 bugs in January.

The Apple patch can be downloaded and installed via the Software Update feature in Mac OS X, or from Apple Downloads.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 115 Talkback(s)
And, by user opinon or momentum, more ppl use Windows
it just a fact. Maybe they don't enjoy using it, or maybe they do, but numbers show that again and again, for love or hate of the security model and patches, they return. There' no comparison.... (Read the rest)
Posted by: Boot_Agnostic Posted on: 03/21/07 You are currently: a Guest | | Terms of Use
Apple megapatch plugs 45 security holes  Loverock Davidson | 03/13/07
And?  jbravo556 | 03/13/07
And!  Loverock Davidson | 03/13/07
Get a Mac and be done with it  mlindl | 03/20/07
I'll stick with Windows  NonZealot | 03/14/07
how do you arrive at the figure 4500?  galileon | 03/14/07
OS9 had thirty-something viruses, trojans, etc.  MacGeek2121 | 03/14/07
Is that actually true?  John Zern | 03/14/07
The worst virus is the wetware running the mouse  ajole | 03/14/07
*with* anti-virus  NoMSfan | 03/14/07
they need Virus Definitions  MacGeek2121 | 03/14/07
And I wouldn't trade the freedoms  xuniL_z | 03/14/07
I hope that was in jest  doh123 | 03/15/07
Vast Freedoms...  Jkirk3279 | 03/15/07
98.7% will do  A_Selby | 03/14/07
I'm sure if anyone ever discovered a real virus on Mac OSX  MacGeek2121 | 03/14/07
But how about this  John Zern | 03/14/07
Oh my God!  cashaww | 03/14/07
You'll stick with illogic  John Sawyer | 03/15/07
The Fact-Free zone continues  mlindl | 03/20/07
Windows is a victim of its own success  A_Selby | 03/14/07
Installed XP the other day...  jasonp@... | 03/14/07
That's exactly right (NT)  Badgered | 03/14/07
Yes. Spend your money where your ethics is. Dont support what you dont like  nomorems | 03/14/07
Installed XP P,Mac Tiger,SuSe,Debian  seapalmer | 03/14/07
Couldn't have put it better...  A_Selby | 03/14/07
There is...  cashaww | 03/14/07
Lovey's back in first place  jorjitop | 03/14/07
You think not, nor can you count.  deleweye | 03/20/07
Nice FUD  Rick_K | 03/13/07
ZDNet is a NBM group?  toadlife | 03/13/07
Is it a service pack?  PB_z | 03/13/07
It's like xp sp2  Rick_K | 03/14/07
300 MB XPSP2 download is for the standalone install  PB_z | 03/14/07
OSX has a lot of service packs!!  NonZealot | 03/14/07
At least Apple is *doing* something  fde101 | 03/14/07
Just ignore WinZealot  Rick_K | 03/14/07
In case it slipped your mind  zkiwi | 03/14/07
Happy  NoMSfan | 03/14/07
Actually, Microsoft slipped a month  3D0G | 03/14/07
Huh?  NonZealot | 03/14/07
And....  zkiwi | 03/14/07
what do you care?  snoople | 03/14/07
Huh???  John Sawyer | 03/15/07
then buy a service pack....  JoeMama_z | 03/14/07
You caught a tiger by the tale their  Boot_Agnostic | 03/21/07
Oh, and in case you can't read  zkiwi | 03/14/07
Patching is good! Negative spin on patching is bad.  MacGeek2121 | 03/14/07
Windows is not a disaster  A_Selby | 03/14/07
Here is my....  cashaww | 03/14/07
Agree with you  Boot_Agnostic | 03/15/07
Tell us your personal experience  NoMSfan | 03/14/07
Simple question  frgough | 03/14/07
This coming from the person who doesn't even know what the word BUILD means  Scrat | 03/14/07
You already know  frgough | 03/14/07
What the hell!  cashaww | 03/14/07
Simple answer  NoMSfan | 03/14/07
Honesty  frgough | 03/14/07
"Honesty you it is bringing the first step towards knowledge"?  A_Selby | 03/14/07
I am lost.  cashaww | 03/14/07
It's a simple question, if phrased correctly  Badgered | 03/14/07
Sorry  frgough | 03/14/07
Not really  Badgered | 03/14/07
Houses and patches  ITguy5678 | 03/14/07
Which simply shows the "personal experience" question...  rx7racer | 03/14/07
Now that's a good response.  A_Selby | 03/14/07
Exploits DO exist for OSX  NonZealot | 03/14/07
You run Linux???  zkiwi | 03/14/07
zkiwi: OSX is BSD?  NonZealot | 03/15/07
re: Which simply shows the "personal experience" question...  Badgered | 03/15/07
So...  zkiwi | 03/16/07
This is  cashaww | 03/14/07
A poll of one is meaningless  John Sawyer | 03/16/07
A poll of one is an Opinion  Badgered | 03/16/07
I have never had any malware problems on my Mac.  MacGeek2121 | 03/14/07
Is that what macinsquash users are calling it?  Rock_Built@... | 03/14/07
I'm sorry, but...  msalzberg | 03/14/07
Sorry!  Rock_Built@... | 03/15/07
Fanboy  A_Selby | 03/14/07
Oh?  ITguy5678 | 03/14/07
Consider everything...  smdunn | 03/15/07
How about facts?  ITguy5678 | 03/15/07
How about facts?  ITguy5678 | 03/15/07
out of curiosity  Badgered | 03/16/07
Error on server  ITguy5678 | 03/19/07
How about facts?  ITguy5678 | 03/15/07
How about facts?  ITguy5678 | 03/15/07
get a clue  kkimball21@... | 03/20/07
And, by user opinon or momentum, more ppl use Windows  Boot_Agnostic | 03/21/07
45 is still 45  Boot_Agnostic | 03/14/07
wow  Badgered | 03/14/07
Well said  NoMSfan | 03/14/07
LOL!  RocketEater | 03/14/07
Actually there is  NoMSfan | 03/14/07
Don't forget  frgough | 03/14/07
to be honest  Badgered | 03/14/07
Amazing?  tic swayback | 03/14/07
So now you are back to  xuniL_z | 03/14/07
Huh?  tic swayback | 03/15/07
Now hopefully mac users will apply the update...  JoeMama_z | 03/14/07
Hahaha!  xxn1927 | 03/14/07
Hahaha hahaha  tic swayback | 03/14/07
mac-patch...  bgonetoo | 03/15/07
Another "NonZealot" oddity  John Sawyer | 03/16/07
just one question  Badgered | 03/16/07
And the answer  John Sawyer | 03/16/07
It is not a given. It is an assumption.  Badgered | 03/16/07
"NonZealot" has one good point  John Sawyer | 03/16/07
No exploits for Apple?  derekgore | 03/16/07
Exploits vs propagation  John Sawyer | 03/16/07
But in those 5 years  John Zern | 03/18/07
New code means new bugs  John Sawyer | 03/19/07
Not all OSX users need it...  alieninvader@... | 03/20/07
Name the successful exploits for OSX  mlindl | 03/20/07
here  the_fiddler_on_the_roof | 03/20/07

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

Meet Doc

  • Here to help you with your Document Management Needs
  • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
  • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
  • Produced by
    ZDNet and
advertisement
Click Here