$bbtitle
AAPL: 183.45 ( -1.61 ) AppleInsider RSS Feed
Search:
AppleInsider.com Archives Reviews Anonymous Mailer Submit Story AppleInsider Forums Polls Advertise on AppleInsider Contact AppleInsider
MacMall: $75 and $100 rebates on the new Penryn MacBooks and $150 rebates on the new Penryn MacBook Pros
Tuesday, March 18, 2008

Apple releases Security Update 2008-002

By AppleInsider Staff

Published: 05:00 PM EST

Apple on Tuesday afternoon released a massive security update targeting various versions of its Mac OS X and Mac OS X Server operating systems, and patching over 40 previously discovered flaws.

Among the most heavily addressed areas are AppKit, the CUPS unix printing environment, Foundation, and X11 -- all of which contained vulnerabilities that could lead to arbitrary code execution, unexpected application termination, or grant attackers unauthorized access to various system components.

A number of password and authentication issues were also addressed in the areas of Kerberos, Podcaster, Preview and Printing. For example, Apple said Mac OS X Server's Podcast Producer included a component that provided passwords to a subtask through arguments, potentially exposing the passwords to other local users. Likewise, Preview and Printing services contained flaws that could expose the contents of an encrypted PDF without prompting the user for a password.

Meanwhile, an Image Raw-related glitch made it possible for a maliciously crafted image to lead to an unexpected application termination or arbitrary code execution.

"A stack based buffer overflow exists in the handling of Adobe Digital Negative (DNG) image files. By enticing a user to open a maliciously crafted image file, an attacker may cause an unexpected application termination or arbitrary code execution," Apple said. "This update addresses the issue through improved validation of DNG image files. This issue does not affect systems prior to Mac OS X v10.5."

Other fixes address vulnerabilities in Apache, AFP, Application Firewall, CFNetwork, ClamAV, CoreFoundation, CoreServices, curl, Emacs, libc, mDNSResponder, notifyd, OpenSSH, pax archive utility, PHP, System Configuration, UDF, and Wiki Server. A full list is available here.

Security Update 2008-002 is available in three distinct distributions each for Mac OS X Client (Leopard, Universal, PPC) and Mac OS X Server (Leopard, Universal, PPC). Alternatively, you can run the Mac OS X Software Update mechanism located under the Apple menu to automatically receive the appropriate update for your system.

Filed under : Mac OS X 17 Comments ] 
Story topics: Security Updates  [ Tell a Friend ] [ Print ] [ Story Link ] 

$150 rebates on all the new
Penryn-based MacBook Pros
$75-$100 rebates on all the new
Penryn-based MacBooks
$75-$125 rebates on all the new
MacBook Air sub-notebook
$50-$100 rebates on all the most
recent iMac desktops
Mac Poker players can play Full Tilt Poker for Mac and get 100% to $600 free with bonus code MP600, courtesy of Online Poker Mac
AppleInsider Features
Hot Forum Topics

Recent Articles
Apple settlements: Canadian iPod credit, notebook adapter refunds
Job listings hint at multi-carrier iPhone in Australia, Brazil
Briefly: Mac OS X 10.5.3; AT&T iPhone hotspot access; Vista sales
Apple developing 3D gaming controller for Apple TV
O2 says Apple's iPhone "no longer available" [updated x2]
NBC prefers Zune DRM [U]; VMware beta; iMac's 10th birthday
America Movil to sell Apple's next-gen iPhone in Mexico
Briefly: Spain, Poland iPhone talk; iPhone SDK beta 5; AT&T memo
Flash Wars: Adobe Fights for AIR with the Open Screen Project [Part 3 of 3]
NBC at iTunes UK; Caris and Piper outlooks; new '3G iPhone' photo
Apple to begin selling 3G iPhone in late June?
More unofficial Mac clones up for sale on eBay
Flash Wars: The Many Enemies and Obstacles of Flash [Part 2 of 3]
Apple to offer iPhone in Italy through multiple carriers
Vodafone inks deal with Apple to sell iPhone in ten countries
Boston's flagship store set to open May 16th
RBC sees 3G, new carrier model driving iPhone sales of 14M
Apple's cash; new 10.5.3 seed; 3G iPhone photos; Boston store size
AmTech's Wu pulls 180, reinstates Buy rating on Apple shares
Handwriting recognition interface appears in iPhone Software 2.0
iPhone SDK goes international, T-Mobile on 3G iPhone in Austria
Flash Wars: Adobe in the History and Future of Flash [Part 1 of 3]
Microsoft steps back from Yahoo bid
iTunes movies sold at loss; MBP display stripes; Microsoft and Yahoo
Video speed test: 2.5G EDGE iPhone vs. mock 3G HSDPA iPhone
UK's Carphone Warehouse now completely out of iPhones
iPhone Optus rumor; Apple TV allows movie sales; Mac web share
Apple on MacBook Air, Jobs' plane, leases, R&D, NAND flash, more...
Safari for Windows market share triples following SW Update push
Piper Jaffray addresses 15 more 'unanswered Apple questions'
Apple announces same day as DVD release iTunes movie sales [u]
iPhone redesign details; washed out MBP screens; free AT&T Wi-Fi
Apple's bionic ARM to muscle advanced gaming graphics into iPhones
MacBook Pro with custom 128GB SSD upgrade benchmarked
WWDC extension; Radeon HD 3870; MacBook Air EVDO hack
10.5.3 Server details; Apple updates; iPhone exclusivity in question
Apple plans retail tweaks as Fenway teaser appears in Boston
Paper: 3G iPhone smaller, lighter than existing model [u]
BlackBerry maker in "confidential" hunt for iPhone developers
It's official: Rogers to bring iPhone to Canada later this year

AppleInsider Market Place

Sell your Laptop - working or not. Free shipping.: Get an instant online quote and sell your laptop today !

Believe in Office: Save Up To 25% on Office 2004 For Mac. Visit Our Site for Details!

IBackup - SMB Online Backup: IBackup is the preferred online storage and backup service of choice for SMBs for its ease of use, security and value. Offers automated backup and restore, file selection and securiy.

Download free software - everyday updated freeware files

 
Advertisements







AppleInsider RSS Feed
AppleInsider © 1997-2008
Please review our Privacy Policy.
Written/Edited/Compiled by the AppleInsider Staff.