Apple releases security update for Mac OS X and OS X Server v. 10.4.11

May 29th, 2008 by Elinor Mills

Apple has released a hefty security update for the Mac OS X and OS X Server that fixes more than 40 vulnerabilities, a number of which could be exploited to enable someone to run programs on the machine remotely or lead to the disclosure of sensitive data.

Security Update 2008-003 is for Mac OS X v. 10.4.11 and Mac OS X Server v. 10.4.11. The fixes are included in the latest Leopard edition, Mac OS X v. 10.5.3, which also was released this week.

The software fixes vulnerabilities that could have led to arbitrary code execution and/or unexpected application termination related to the implementation of: AFP Server, AppKit, Apple Pixlet Video, ATS, CoreFoundation, CoreGraphics, Flash Player Plug-in, Help Viewer and iCal. The iCal vulnerability was discovered by Core Security, which last week announced it had found three vulnerabilities in iCal.

It also fixes vulnerabilities that could have led to disclosure of sensitive information related to the implementation of technologies including CUPS, International Components for Unicode, and CFNetwork when visiting a maliciously crafted website due to an issue in Safari's SSL client certificate handling.

Meanwhile, other updates fix vulnerabilities that could lead to information disclosure and allow a local user to manipulate files with the privileges of another user in Mail; allow a remote attacker to read arbitrary files related to Ruby; expose passwords supplied to sso_util to other local users when using Single Sign-On; expose user names on servers with Wiki Server enabled to a remote attacker; and not warn users before opening certain potentially unsafe content types.

In addition, the software fixes a vulnerability that could lead to information disclosure when viewing a maliciously crafted BMP or GIF image and lead to unexpected application termination or arbitrary code execution when viewing a maliciously crafted JPEG2000 image file.

Security Update 2008-003 and Mac OS X v. 10.5.3 are available from Apple's Software Downloads website.

Share and Enjoy:

These icons link to social bookmarking sites where readers can share and discover new web pages.
  • del.icio.us
  • Digg
  • NewsVine
  • Reddit
  • Slashdot
  • StumbleUpon
  • Technorati

Be the first to comment on this article!

Add your opinion

* indicates information we require to process your submission





Your e-mail will not be displayed
You must read and type the 6 chars within 0..9 and A..F
You must read and type the 6 chars within 0..9 and A..F