On CBS.com: HD may burn your eyes
BNET Business Network:
BNET
TechRepublic
ZDNet

By Dawn Kawamoto, News.com
Posted on ZDNet News: Nov 30, 2005 4:02:00 PM

Apple Computer has issued "highly critical" security updates to address more than a dozen vulnerabilities in its Mac OS X operating system.

Apple released on Tuesday security patches for Mac OS X 10.4.3, otherwise known as Tiger, as well as Mac OS X 10.3.9, dubbed Panther, according to the company's advisory.

Thirteen security flaws were found in areas related to the Apache 2 Web server, curl technology and the Safari browser. The vulnerabilities ranged from potentially letting an attacker launch a denial-of-service attack to taking control of a person's system remotely.

"The most severe of these are the vulnerabilities found in curl and the PCRE library used by Safari," said Thomas Kristensen, chief technology officer for security site Secunia, which rated Apple's updates as "highly critical"--the second-highest danger ranking.

A large number of applications could be affected by the vulnerability in the PCRE library used by Safari's JavaScript engine, Kristensen said. People who inadvertently click on a malicious Web site with their Safari browser could find the flaw exploited, leading to a remote execution of code on their system.

A flaw in Apple's curl technology, which is a library frequently used to download large files and pass them along, could be exploited if visiting a malicious Web site. The site, once detecting curl technology is present on a user's system, can take advantage of the security flaw, Kristensen said. That could result to a remote execution of code on a computer.

One security flaw addressed in the update involves a boundary error found in WebKit. This marks the second time in four months that Apple has addressed a flaw in WebKit, Kristensen said.

This latest flaw could let an attacker launch a buffer overflow, or denial of service attack, that could also lead to a remote execution of code and control of a person's system. The earlier flaw in WebKit dealt with the handling of PDF documents.

The new Mac OS X patches follow one issued earlier this month by Apple to address vulnerabilities in four areas of its operating system.

Apple was not available for immediate comment.

  • Talkback
  • Most Recent of 95 Talkback(s)
Doh!
I hope the phrase "to ignorrant" does not refer to me? Perhaps
you would be better rephrasing your posts so they are not read
offensively. Yes, I checked that. I can also write a program to do... (Read the rest)
Posted by: mbrierley Posted on: 04/18/06 You are currently: Logged In | Log out
COOL...you just have to love the patch BEFORE the problem! Laff   | 11/30/05
F*ck That, I Love The Nimrod ZDNet Poster nikoli   | 11/30/05
Well if there are no exploits then you are and will be wrong! Laff   | 11/30/05
I think you miss the point somewhat phogue@...   | 11/30/05
I don't think there are exploits cause that WOULD be news! Laff   | 11/30/05
Exicting exploits phogue@...   | 11/30/05
I agree in total and to your last point..that is why I use the Mac. Laff   | 11/30/05
I agree in total and to your last point..that is why I use the Mac. Laff   | 11/30/05
Bottom line... gfeier   | 11/30/05
gfeier... nikoli   | 11/30/05
It's extremely difficult to hack a Mac.... Mikael_z   | 11/30/05
Care to restate? NonZealot   | 11/30/05
APay him no mind Non-Zealot as.. John Zern   | 11/30/05
No, we have a REAL sense of security. Haterock Davidsfather   | 11/30/05
Hard To Hack Mac Unless You Use These Holes? PMC-CON   | 11/30/05
Haterock, So The Safari Holes and Webkit Don't Count? PMC-CON   | 11/30/05
Message has been deleted. Haterock Davidsfather   | 11/30/05
Haterock, You're No Loverock PMC-CON   | 11/30/05
All aboaaaaard. The ignorance train is leaving! toadlife   | 01/07/06
Or perhaps I'm Ye, the MS SHILL .   | 11/30/05
Famous for hacking Macs????? phogue@...   | 12/01/05
Why not target Macs? timoute   | 12/01/05
Why get know for creating illegal code? phogue@...   | 12/01/05
Only adds ammunition to the "biggest target" theory NonZealot   | 11/30/05
I agree phogue@...   | 11/30/05
Complacent MacOS users jimkahnw   | 11/30/05
Auto Update phogue@...   | 11/30/05
The only AV any of the Nix's Linux Advocate   | 11/30/05
Macs Firewall phogue@...   | 12/01/05
Too much effort mbrierley   | 11/30/05
I don't think I disagree with the biggest target claim however Laff   | 11/30/05
Overconfident..naw! PLEASED....yup! Laff   | 11/30/05
10.4 upgrade is biggest threat... mmckee58   | 11/30/05
Trust me Gates needs no leasons on getting away with MURDER!!! Laff   | 11/30/05
10.4 upgrade is biggest threat... phogue@...   | 11/30/05
Apple's famous for that John Zern   | 11/30/05
Where are your facts? Rick_K   | 12/01/05
Huh? tic swayback   | 11/30/05
a reliable source...possibly... mmckee58   | 12/06/05
a reliable source...possibly... mmckee58   | 12/06/05
a reliable source...possibly... mmckee58   | 12/06/05
Biggest target theory has some validity, georgep_z   | 11/30/05
lots of factors MacKeyser   | 11/30/05
Just for the recoed phogue@...   | 12/01/05
You're kidding, right? toadlife   | 01/07/06
Other reasons tic swayback   | 11/30/05
Thanks for the response NonZealot   | 11/30/05
Huh? Len Rooney   | 11/30/05
I just wish you were generally nicer and had a great day Boot_Agnostic   | 11/30/05
Hehe, you made me chuckle NonZealot   | 11/30/05
Speculation tic swayback   | 11/30/05
Hacking Windows because they hate Microsoft??? phogue@...   | 11/30/05
Not all exploits are for profit tic swayback   | 11/30/05
RE: Not all exploits are for profit phogue@...   | 12/01/05
How do you know? tic swayback   | 12/01/05
The "Target with Gaping Security Holes" Theory buddhistMonkey   | 11/30/05
Re: The "Target with Gaping Security Holes" Theory phogue@...   | 12/01/05
Marketshare? Fred Fredrickson   | 12/01/05
"biggest target" theory FLAWED Hard Cider   | 12/03/05
Even you need to admit IT Scion   | 11/30/05
Not really tic swayback   | 11/30/05
Weren't IT Scion   | 12/01/05
Do other companies do this? tic swayback   | 12/01/05
Somewhat unrealistic Fred Fredrickson   | 12/01/05
Beware of complacency Carrion   | 11/30/05
Beware of Complacency phogue@...   | 11/30/05
I agree completely... Carrion   | 11/30/05
Without defintitions, AV software is useless tic swayback   | 11/30/05
AV software mbrierley   | 12/01/05
Re: Without defintitions, AV software is useless phogue@...   | 12/01/05
I run AV as well tic swayback   | 12/01/05
Doh! mbrierley   | 04/18/06
Security is a Process, NOT AN END deanoa   | 11/30/05
No one can start a process without asking for.... Mikael_z   | 11/30/05
*nix like OSX is still more secure than windows jtoppi   | 11/30/05
I think that assumpition is incorrect... ju1ce   | 12/01/05
So is that one Fred Fredrickson   | 12/01/05
WHY SUCH PATCHES MAKE THE WEB NEWS? fakir005@...   | 11/30/05
Oh wow man I'm Ye, the MS SHILL .   | 11/30/05
Smart decision! An_Axe_to_Grind   | 11/30/05
Choir preaching? sdwood   | 11/30/05
winzealot and other astroturfers pablo@...   | 12/01/05
Typhoon victims phogue@...   | 12/01/05
I thought it was all market share... TheCrow_z   | 12/01/05
LMAO @ Chicken Little phogue@...   | 12/01/05
Suse Linux 10 2-cycle   | 12/01/05
My friend I'm Ye, the MS SHILL .   | 12/01/05
Imagine a news story for MS patches chasisaac   | 12/01/05
Built in Security Features?! Andromedat6   | 12/01/05
Re:Built in Security Features?! phogue@...   | 12/02/05
Built in Security Features?! Andromedat6   | 12/01/05
Built in Security Features?! Andromedat6   | 12/01/05
More Mac-Hating nonsense theMacDaddy   | 12/01/05
Re:More Mac-Hating nonsense phogue@...   | 12/02/05
Bottom Line phogue@...   | 12/02/05

What do you think?

advertisement
advertisement
Click Here