$bbtitle
Apple Stock: 140.02 ( -2.81 )
RSS RSS Twitter Twitter
Search:
AppleInsider.com Archives News Bytes Reviews Anonymous Mailer Submit Story AppleInsider Forums Mac Prices Polls Advertise on AppleInsider Contact AppleInsider
Save up to $250 on new MacBook Pros and up to $180 on new iMacs: Mac Pricing Guide updated July 3rd (Find the best prices on Macs).
Thursday, April 19, 2007

Apple patch tackles two dozen Mac OS vulnerabilities

By Slash Lane

Published: 04:00 PM EST

Apple Inc. on Thursday plugged over two dozen security exploits within the client and server versions of its Mac OS X 10.3 "Panther" and Mac OS X 10.4 "Tiger" operating systems that could potentially expose Mac users to a variety of malicious attacks.

For Mac OS X 10.4.9

A version of the software update for systems running Mac OS X 10.4.9 -- labeled Security Update 2007-004 -- does away with vulnerabilities affecting AFP Client, AirPort, CarbonCore, diskdev_cmds, fetchmail, ftpd, gnutar, Help Viewer, HID Family, Installer, Kerberos, Libinfo, Login Window, network_cmds, SMB, System Configuration, URLMount, Video Conference and WebDAV.

The patch is available as a 16.1MB download for Macs running the Intel version of Mac OS X 10.4.9 client version and as a 9.3MB download for those machines running the PowerPC version of the OS.

For Mac OS X 10.3.9

Apple has also made a version of the security update available for systems running the most recent point release of its previous-generation Mac OS X 10.3 "Panther" software. That release dismantles exploits in AFP Client, AirPort, diskdev_cmds, fetchmail, ftpd, Help Viewer, Kerberos, Libinfo, Login Window, network_cmds, SMB, System Configuration, URLMount, Video Conference, WebDAV and WebFoundation.

Users of 10.3.9 can download a 37.6MB updater for the client version of the software or a 54.1MB updater for its server counterpart.

The culprits

For the most part, the vulnerabilities addressed by the Mac maker's latest security update could translate into denial of service attack, unexpected application termination, or arbitrary code execution. However, Apple made note of several more critical issues that could allow malicious users to gain elevated system privileges through AFP Client, Airport, CarbonCore, Kerberos, WebDav and the Mac OS X Login Window.

The Cupertino-based company also addressed two other significant shortcomings of the Login Window. The first, resulting from insufficient checks of environmental variables, could allow local user to obtain system privileges and execute arbitrary code. The other, meanwhile, would at times allow the screen saver authentication dialog to be bypassed without entering a password even when a user had set his or her preference to "require a password to wake the computer from sleep."

42 Comments ] 
  Print ] [ Story Link ] 


(13") $1,094.00 (15") $1,579.00 (15") $2,089.00
(13") $1,394.00 (15") $1,799.00 (17") $2,249.00
See more prices in AppleInsider's Mac Price Guide
Mac Poker players can play Full Tilt Poker for Mac and get 100% to $600 free with bonus code MP600, courtesy of Online Poker Mac
AppleInsider Features
Hot Forum Topics

Recent Articles
Countering rumor says Apple and NVIDIA "doing just fine"
Breaking: shot fired, one wounded at Virginia-based Apple Store
First iPhone 3GS jailbreaking tool available for download
iPhone 3GS marked AT&T's "best-ever sales day"
iPhone overheating problems could see aid from new patent
Apple working to fix unreleased iPhone SMS exploit
Pesky Psystar to emerge from Chapter 11 with new Mac offering
Apple looks towards fingerprint-based multi-touch controls
Apple developing "active packaging" for iPods and iPhones
Apple may drop NVIDIA chips in Macs following contract fight
Apple covering all the bases with Mac OS X 10.5.8 betas
University of Florida's PharmD program to require iPod touch
Apple's Mac shipments rebounding sharply in recent weeks
iPhone Software 3.1 to deliver new video and Voice Control features
Apple posts iPhone OS 3.1 beta, SDK with new video extensions
White iPhone 3GS units discoloring from excessive heat
Maine's expanded MacBook program the 'largest of its kind'
Mozilla releases faster, safer, smarter version of Firefox browser
Dell working on pocket-sized Internet gadget
MacBook Air firmware updated to support replacement batteries
Apple sees brief iPhone 3GS shortages; NVIDIA intros CS4 plugins
Steve Jobs returns to work at Apple
Apple, other phone makers agree on standard charger for Europe
Apple posts new Snow Leopard, 10.5.8 seeds
iPhone marketing head goes to VC firm; iTunes breaks records after Jackson death
Briefly: more affordable iMacs from Apple expected by fall
Apple's latest high-end MacBook Air slower than predecessor
Apple's profit margin on Mac minis slimmer than usual
Apple ups stake in iPhone graphics chip designer
Windows 7 priced below Vista, to allow upgrades from XP
Mossberg: New MacBook Pro has best battery life "ever tested"
Apple sued over 'false' iTunes gift card promises
Proof-of-concept ports Leopard's icon stacks to iPhone (video)
iPhone 3GS spurs 400% increase in mobile video uploads to YouTube
Tidbit: Apple naming Leopard point release after ancient gods
Upgrade fee sees few iPod touch users updating to 3.0 software
Apple exploring wireless system for quantifying the unquantifiable
Bogged down AT&T 3G to clear in months; Buffett criticizes Jobs
Apple updates Apple TV, Remote app to allow multi-touch control [u]
Apple undersells, over-delivers on iPhone 3GS speed - report

AppleInsider Market Place

Sell your Laptop - working or not. Free shipping.: Get an instant online quote and sell your laptop today !

Believe in Office: Save Up To 25% on Office 2004 For Mac. Visit Our Site for Details!

IBackup - SMB Online Backup: IBackup is the preferred online storage and backup service of choice for SMBs for its ease of use, security and value. Offers automated backup and restore, file selection and securiy.

Download free software - everyday updated freeware files

 
Advertisements








AppleInsider RSS Feed
AppleInsider © 1997-2008
Please review our Privacy Policy.
Written/Edited/Compiled by the AppleInsider Staff.