$bbtitle
AAPL: 92.47 ( +3.54 ) AppleInsider RSS Feed
Search:
AppleInsider.com Archives Reviews Anonymous Mailer Submit Story AppleInsider Forums Polls Advertise on AppleInsider Contact AppleInsider
AppleInsider's Mac Pricing Matrix updated December 2nd (Find the best prices on Macs).
Thursday, July 31, 2008

New Mac OS X Security Update patches dangerous DNS hole

By Aidan Malley

Published: 11:40 PM EST

Apple late on Thursday offered up its fifth security update of 2008 to cover an industry-wide and potentially dangerous exploit of Domain Name System server access for spoofing attacks.

Security Update 2008-005 is available for client versions of Mac OS X Leopard (65MB) and Tiger (Intel, PowerPC) as well as Tiger Server (Intel, PowerPC).

Among the multiple fixes, the most essential is one for the Berkeley Internet Name Domain server feature in the operating system, or BIND. While not enabled by default, the service when switched on is potentially vulnerable to exploits of a fundamental flaw in the DNS system that helps govern the Internet protocol and translates website names (such as appleinsider.com) to IP addresses.

Any computer left exposed and unpatched against the attack, regardless of operating system, can have its DNS cache "poisoned," tricking the computer into visiting a malicious website even when the user chooses to visit what would normally be a legitimate address. The Apple fix randomizes the source port for DNS information and so prevents an easy attack when BIND is active.

Other security updates are also rolled into the update and include guards against arbitrary code execution in CarbonCore, CoreGraphics, Data Detectors, Disk Utility, OpenLDAP, Open Scripting Architecture, OpenSSL, PHP, and rsync.

Mac OS X Leopard users are specifically affected by a potential exploit in the software's QuickLook feature and its handling of Microsoft Office files that could allow malicious code.

Filed under : Mac OS X 24 Comments ] 
Story topics: Leopard, Tiger   Print ] [ Story Link ] 


Parallels 4.0
Mac Poker players can play Full Tilt Poker for Mac and get 100% to $600 free with bonus code MP600, courtesy of Online Poker Mac
AppleInsider Features
Hot Forum Topics

Recent Articles
Apple looking into liquid-cooled MacBooks
Apple's Snow Leopard still evolving, developers say
iPhone single-handedly driving smartphone growth
Apple finally taking orders for new in-ear headphones
Apple now "encourages" antivirus use for Mac OS X
High-quality unboxing photos of Apple's LED Cinema Display
Apple pushing Mini DisplayPort through no-fee licenses
Apple opening first German retail store in Munich this weekend
Apple a 'bright spot' during lackluster Black Friday kick-off
VMWare offering 50% off Fusion 2.0 for Cyber Monday
iPhone Dev Team successfully boots Linux on iPhone
Black Friday Mac pricing matrix (find the best prices)
Apple's Black Friday Sale: $101 off some MacBooks and iMacs
Black Friday at Amazon: cameras, GPS, hard drives, and more
Black Friday: Office 2008, Parallels, Quicken, Adobe
Google testing Picasa for Mac beta
iPhone 2.2 hides video out code for third-party apps
Apple investigating graphics issues on new MacBook lines
Early deals: $250 off new MacBook Pros, $325 off Office 2008
Apple's Black Friday discounts may rise to 15%, says firm
QuickTime 7.5.7 allows SD iTunes playback over DisplayPort
Mac small business share nearly triples over the summer
Apple's unadvertised retail store price matching policy
Talks to bring The Beatles to iTunes break down
Piper Jaffray addresses 12 more 'unanswered Apple questions'
Apple lays claim to greenest notebooks ever in new ad campaign
Apple stock surges on belief MacBooks "peel away" Windows users
Apple sued over mobile Safari as email retention policy questioned
Microsoft developing NVIDIA-based mobile phone - report
LG holds iMac-suitable touchscreen; new iTunes plus hints
Best Buy cuts prices on Apple's Mac line for 4-day sale [u]
Apple, Palm taking different steps to reduce worker overhead
Dining out with iPhone: Zagat and OpenTable hit the App Store
Apple updates Final Cut Pro, Compressor, Color, and Shake
Apple releases iPhone Software v2.2
Apple releases iTunes 8.0.2 ahead of iPhone software 2.2
iPhone security posting suggests 2.2 firmware tomorrow
Apple now No. 2 in corporate smartphone market share
Review roundup: RIM's new touchscreen BlackBerry Storm
Apple authorizes MMS on the iPhone, but not for US users

AppleInsider Market Place

Sell your Laptop - working or not. Free shipping.: Get an instant online quote and sell your laptop today !

Believe in Office: Save Up To 25% on Office 2004 For Mac. Visit Our Site for Details!

IBackup - SMB Online Backup: IBackup is the preferred online storage and backup service of choice for SMBs for its ease of use, security and value. Offers automated backup and restore, file selection and securiy.

Download free software - everyday updated freeware files

 
Advertisements








AppleInsider RSS Feed
AppleInsider © 1997-2008
Please review our Privacy Policy.
Written/Edited/Compiled by the AppleInsider Staff.