$bbtitle
AAPL: 82.58 ( +2.09 ) AppleInsider RSS Feed
Search:
AppleInsider.com Archives Reviews Anonymous Mailer Submit Story AppleInsider Forums Polls Advertise on AppleInsider Contact AppleInsider
Run Windows on your Mac: Download Parallels 4.0 today. Now 50% faster. Upgrades: $39.99. New licenses $79.99.
Thursday, April 19, 2007

Apple patch tackles two dozen Mac OS vulnerabilities

By Slash Lane

Published: 04:00 PM EST

Apple Inc. on Thursday plugged over two dozen security exploits within the client and server versions of its Mac OS X 10.3 "Panther" and Mac OS X 10.4 "Tiger" operating systems that could potentially expose Mac users to a variety of malicious attacks.

For Mac OS X 10.4.9

A version of the software update for systems running Mac OS X 10.4.9 -- labeled Security Update 2007-004 -- does away with vulnerabilities affecting AFP Client, AirPort, CarbonCore, diskdev_cmds, fetchmail, ftpd, gnutar, Help Viewer, HID Family, Installer, Kerberos, Libinfo, Login Window, network_cmds, SMB, System Configuration, URLMount, Video Conference and WebDAV.

The patch is available as a 16.1MB download for Macs running the Intel version of Mac OS X 10.4.9 client version and as a 9.3MB download for those machines running the PowerPC version of the OS.

For Mac OS X 10.3.9

Apple has also made a version of the security update available for systems running the most recent point release of its previous-generation Mac OS X 10.3 "Panther" software. That release dismantles exploits in AFP Client, AirPort, diskdev_cmds, fetchmail, ftpd, Help Viewer, Kerberos, Libinfo, Login Window, network_cmds, SMB, System Configuration, URLMount, Video Conference, WebDAV and WebFoundation.

Users of 10.3.9 can download a 37.6MB updater for the client version of the software or a 54.1MB updater for its server counterpart.

The culprits

For the most part, the vulnerabilities addressed by the Mac maker's latest security update could translate into denial of service attack, unexpected application termination, or arbitrary code execution. However, Apple made note of several more critical issues that could allow malicious users to gain elevated system privileges through AFP Client, Airport, CarbonCore, Kerberos, WebDav and the Mac OS X Login Window.

The Cupertino-based company also addressed two other significant shortcomings of the Login Window. The first, resulting from insufficient checks of environmental variables, could allow local user to obtain system privileges and execute arbitrary code. The other, meanwhile, would at times allow the screen saver authentication dialog to be bypassed without entering a password even when a user had set his or her preference to "require a password to wake the computer from sleep."

42 Comments ] 
  Print ] [ Story Link ] 


Parallels 4.0
Mac Poker players can play Full Tilt Poker for Mac and get 100% to $600 free with bonus code MP600, courtesy of Online Poker Mac
AppleInsider Features
Hot Forum Topics

Recent Articles
Apple, Palm taking different steps to reduce worker overhead
Dining out with iPhone: Zagat and OpenTable hit the App Store
Apple updates Final Cut Pro, Compressor, Color, and Shake
Apple releases iPhone Software v2.2
Apple releases iTunes 8.0.2 ahead of iPhone software 2.2
iPhone security posting suggests 2.2 firmware tomorrow
Apple now No. 2 in corporate smartphone market share
Review roundup: RIM's new touchscreen BlackBerry Storm
Apple authorizes MMS on the iPhone, but not for US users
Apple developing always-on iPhone status indicators
Apple releases Apple TV 2.3 with AirTunes, third-party remotes
Apple's OpenCL standard near complete in just six months
Apple in talks to offer more DRM-free tracks on iTunes [updated]
Microsoft saw Apple's anti-Vista campaign coming
Wal-Mart to begin selling iPhone post holidays - reports
Apple waiting on quad-core desktop chips from Intel
Apple may release Snow Leopard early next year
Reseller sells early MacBook Air prototype on eBay
Judge grants Apple's motion to dismiss Psystar's counterclaims
Apple's new MacBooks have built-in copy protection measures
Apple sees Mac sales rise 28% amid latest notebook launch
Apple now taking orders for 24-inch LED Cinema Display
Google Mobile iPhone app with voice search now available
Adobe shows ARM-ready Flash 10; Spansion names Apple in suit
Apple releases fix for quirky MacBook glass trackpads
Apple flirting with another record quarter for Mac sales
Apple to launch iPhone in Taiwan next month
New seed shows Apple near wrap-up of Mac OS X 10.5.6
New Apple hire fights back in countersuit against IBM
Apple sued over hairline cracks in iPhone 3G casings
Google voice search app for iPhone arriving shortly
Apple job listing hints at iPhone nearing China launch
Apple releases Safari 3.2 with phishing protection
New Intel Xeons offer upgrade path for Mac Pro in early 2009 [u]
Apple could be tailoring its own search engine wrapper
Apple could beat 2009 revenue consensus by $900m per quarter
Apple pushing for patent on versatile tablet docking station
Docs show Apple failed to find ideal successor for iPod chief
Apple may launch most aggressive Black Friday sale yet
Apple improving Mobile Me synching in Mac OS X 10.5.6

AppleInsider Market Place

Sell your Laptop - working or not. Free shipping.: Get an instant online quote and sell your laptop today !

Believe in Office: Save Up To 25% on Office 2004 For Mac. Visit Our Site for Details!

IBackup - SMB Online Backup: IBackup is the preferred online storage and backup service of choice for SMBs for its ease of use, security and value. Offers automated backup and restore, file selection and securiy.

Download free software - everyday updated freeware files

 
Advertisements








AppleInsider RSS Feed
AppleInsider © 1997-2008
Please review our Privacy Policy.
Written/Edited/Compiled by the AppleInsider Staff.