On The Insider: Judge Bans Real Housewives Sex Tape
BNET Business Network:
BNET
TechRepublic
ZDNet

By Dawn Kawamoto
Posted on ZDNet News: Nov 30, 2005 4:02:00 PM

Apple Computer has issued "highly critical" security updates to address more than a dozen vulnerabilities in its Mac OS X operating system.

Apple released on Tuesday security patches for Mac OS X 10.4.3, otherwise known as Tiger, as well as Mac OS X 10.3.9, dubbed Panther, according to the company's advisory.

Thirteen security flaws were found in areas related to the Apache 2 Web server, curl technology and the Safari browser. The vulnerabilities ranged from potentially letting an attacker launch a denial-of-service attack to taking control of a person's system remotely.

"The most severe of these are the vulnerabilities found in curl and the PCRE library used by Safari," said Thomas Kristensen, chief technology officer for security site Secunia, which rated Apple's updates as "highly critical"--the second-highest danger ranking.

A large number of applications could be affected by the vulnerability in the PCRE library used by Safari's JavaScript engine, Kristensen said. People who inadvertently click on a malicious Web site with their Safari browser could find the flaw exploited, leading to a remote execution of code on their system.

A flaw in Apple's curl technology, which is a library frequently used to download large files and pass them along, could be exploited if visiting a malicious Web site. The site, once detecting curl technology is present on a user's system, can take advantage of the security flaw, Kristensen said. That could result to a remote execution of code on a computer.

One security flaw addressed in the update involves a boundary error found in WebKit. This marks the second time in four months that Apple has addressed a flaw in WebKit, Kristensen said.

This latest flaw could let an attacker launch a buffer overflow, or denial of service attack, that could also lead to a remote execution of code and control of a person's system. The earlier flaw in WebKit dealt with the handling of PDF documents.

The new Mac OS X patches follow one issued earlier this month by Apple to address vulnerabilities in four areas of its operating system.

Apple was not available for immediate comment.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 95 Talkback(s)
Doh!
I hope the phrase "to ignorrant" does not refer to me? Perhaps
you would be better rephrasing your posts so they are not read
offensively. Yes, I checked that. I can also write a program to do... (Read the rest)
Posted by: mbrierley Posted on: 04/18/06 You are currently: a Guest | | Terms of Use
COOL...you just have to love the patch BEFORE the problem!  Laff | 11/30/05
F*ck That, I Love The Nimrod ZDNet Poster  nikoli | 11/30/05
Well if there are no exploits then you are and will be wrong!  Laff | 11/30/05
I think you miss the point somewhat  phogue@... | 11/30/05
I don't think there are exploits cause that WOULD be news!  Laff | 11/30/05
Exicting exploits  phogue@... | 11/30/05
I agree in total and to your last point..that is why I use the Mac.  Laff | 11/30/05
I agree in total and to your last point..that is why I use the Mac.  Laff | 11/30/05
Bottom line...  gfeier | 11/30/05
gfeier...  nikoli | 11/30/05
It's extremely difficult to hack a Mac....  Mikael_z | 11/30/05
Care to restate?  NonZealot | 11/30/05
APay him no mind Non-Zealot as..  John Zern | 11/30/05
No, we have a REAL sense of security.  Haterock Davidsfather | 11/30/05
Hard To Hack Mac Unless You Use These Holes?  PMC-CON | 11/30/05
Haterock, So The Safari Holes and Webkit Don't Count?  PMC-CON | 11/30/05
Message has been deleted.  Haterock Davidsfather | 11/30/05
Haterock, You're No Loverock  PMC-CON | 11/30/05
All aboaaaaard. The ignorance train is leaving!  toadlife | 01/07/06
Or perhaps  I'm Ye, the MS SHILL . | 11/30/05
Famous for hacking Macs?????  phogue@... | 12/01/05
Why not target Macs?  timoute | 12/01/05
Why get know for creating illegal code?  phogue@... | 12/01/05
Only adds ammunition to the "biggest target" theory  NonZealot | 11/30/05
I agree  phogue@... | 11/30/05
Complacent MacOS users  jimkahnw | 11/30/05
Auto Update  phogue@... | 11/30/05
The only AV any of the Nix's  Linux Advocate | 11/30/05
Macs Firewall  phogue@... | 12/01/05
Too much effort  mbrierley | 11/30/05
I don't think I disagree with the biggest target claim however  Laff | 11/30/05
Overconfident..naw! PLEASED....yup!  Laff | 11/30/05
10.4 upgrade is biggest threat...  mmckee58 | 11/30/05
Trust me Gates needs no leasons on getting away with MURDER!!!  Laff | 11/30/05
10.4 upgrade is biggest threat...  phogue@... | 11/30/05
Apple's famous for that  John Zern | 11/30/05
Where are your facts?  Rick_K | 12/01/05
Huh?  tic swayback | 11/30/05
a reliable source...possibly...  mmckee58 | 12/06/05
a reliable source...possibly...  mmckee58 | 12/06/05
a reliable source...possibly...  mmckee58 | 12/06/05
Biggest target theory has some validity,  georgep_z | 11/30/05
lots of factors  MacKeyser | 11/30/05
Just for the recoed  phogue@... | 12/01/05
You're kidding, right?  toadlife | 01/07/06
Other reasons  tic swayback | 11/30/05
Thanks for the response  NonZealot | 11/30/05
Huh?  Len Rooney | 11/30/05
I just wish you were generally nicer and had a great day  Boot_Agnostic | 11/30/05
Hehe, you made me chuckle  NonZealot | 11/30/05
Speculation  tic swayback | 11/30/05
Hacking Windows because they hate Microsoft???  phogue@... | 11/30/05
Not all exploits are for profit  tic swayback | 11/30/05
RE: Not all exploits are for profit  phogue@... | 12/01/05
How do you know?  tic swayback | 12/01/05
The "Target with Gaping Security Holes" Theory  buddhistMonkey | 11/30/05
Re: The "Target with Gaping Security Holes" Theory  phogue@... | 12/01/05
Marketshare?  Fred Fredrickson | 12/01/05
"biggest target" theory FLAWED  Hard Cider | 12/03/05
Even you need to admit  IT Scion | 11/30/05
Not really  tic swayback | 11/30/05
Weren't  IT Scion | 12/01/05
Do other companies do this?  tic swayback | 12/01/05
Somewhat unrealistic  Fred Fredrickson | 12/01/05
Beware of complacency  Carrion | 11/30/05
Beware of Complacency  phogue@... | 11/30/05
I agree completely...  Carrion | 11/30/05
Without defintitions, AV software is useless  tic swayback | 11/30/05
AV software  mbrierley | 12/01/05
Re: Without defintitions, AV software is useless  phogue@... | 12/01/05
I run AV as well  tic swayback | 12/01/05
Doh!  mbrierley | 04/18/06
Security is a Process, NOT AN END  deanoa | 11/30/05
No one can start a process without asking for....  Mikael_z | 11/30/05
*nix like OSX is still more secure than windows  jtoppi | 11/30/05
I think that assumpition is incorrect...  ju1ce | 12/01/05
So is that one  Fred Fredrickson | 12/01/05
WHY SUCH PATCHES MAKE THE WEB NEWS?  fakir005@... | 11/30/05
Oh wow man  I'm Ye, the MS SHILL . | 11/30/05
Smart decision!  An_Axe_to_Grind | 11/30/05
Choir preaching?  frabjous | 11/30/05
winzealot and other astroturfers  theo_durcan | 12/01/05
Typhoon victims  phogue@... | 12/01/05
I thought it was all market share...  TheCrow_z | 12/01/05
LMAO @ Chicken Little  phogue@... | 12/01/05
Suse Linux 10  2-cycle | 12/01/05
My friend  I'm Ye, the MS SHILL . | 12/01/05
Imagine a news story for MS patches  chasisaac | 12/01/05
Built in Security Features?!  Andromedat6 | 12/01/05
Re:Built in Security Features?!  phogue@... | 12/02/05
Built in Security Features?!  Andromedat6 | 12/01/05
Built in Security Features?!  Andromedat6 | 12/01/05
More Mac-Hating nonsense  theMacDaddy | 12/01/05
Re:More Mac-Hating nonsense  phogue@... | 12/02/05
Bottom Line  phogue@... | 12/02/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

Smartphones

  • Last year, many businesses deferred the purchase of new laptops in favor of smartphones, and why not? Offering phone, calendar, email, IM and Web access, they're arguably the most practical business tools. Check out the latest CNET Reviews of Blackberry devices for all the knowledge you need to make an intelligent choice.
  • Designed for
    bold living.
  • blackberry bold
  • Edit Word docs, check email, even listen to iTunes® playlists. Do more and do it faster with the BlackBerry® Bold™.Learn more
  • blackberry logo
advertisement
Click Here