Mac OS X update fails to fix vulnerability

Apple gives lessons in security mismanagement

A major revision of Apple's Mac OS X operating system released this week fails to come bundled with a vital, recently-issued security fix.

A security patch (2004-05-24) which guards against a vulnerability in the Help viewer sub-system is absent from the Mac OS X version 10.3.4, despite claims to the contrary by Apple.

Reg hardware editor Tony Smith found it's necessary to install the patch manually, confirming reports on Mac enthusiast sites. The OS update does not overwrite previously applied patches, however, and these should show up as available via Software Update. That's providing a user bothers to double-check after being told that he/she is told they are perfectly safe by Apple.

This confusion is compounded by Apple, which has thus far failed to address another critical - and easily exploitable - security hole which it wrongly told Techworld was fixed by the Help Viewer patch.

An updated version of a security testing tool by Unsanity establishes that even patched systems are vulnerable. So patched Mac OS X systems are vulnerable and unpatched systems are even more vulnerable.

Unless Apple faces up to the security issues its users face, its reputation for making secure operating systems, already damaged by its mishandling of these recently discovered vulnerabilities, will be further tarnished. ®

Related stories

Apple posts Mac OS X update
Apple patches critical Mac OS X hole (up to a point)
Apple to slow annual OS X update rate

Sponsored: 5 critical considerations for enterprise cloud backup