Feeds

Apple posts second Mac OS X vuln patch

Nabbed

  • alert
  • submit to reddit

Securing Web Applications Made Simple and Scalable

Update Apple has posted a second software update intended to fix a vulnerability that exploits the way Mac OS X handles URI links.

We installed the update, Security Update 2004-06-07, on a Mac OS X 10.3.4 machine. After restarting the machine, we went straight to Unsanity's web site, the location of a pair of web pages that test the URI vulnerability. Neither tests was blocked by the update, details of which can be found here.

The same site provides Paranoid Android, a utility that halts attempts to open apps from URIs and offers the user the choice of proceeding with the attempt or to cancel it.

Security Update 2004-06-07 does the same thin. We initially downloaded the update using Mac OS X's Software Update facility and we tried again using the download posted on Apple's web site.

Unlike Paranoid Android, the code contained in the update remembers applications the user has permitted other applications to open, or those that the user has opened themselves. So it's possible that the system is allowing access to the test site apps because they have already been run prior to the installation of the update.

Certainly a number of Register readers have told us the update works for them with both Unsanity tests.

We'd certainly recommend installing the new update in any case. ®

Related stories

Mac OS X update fails to fix vulnerability
Apple posts Mac OS X update
Apple patches critical Mac OS X hole
Apple picks 15 June for iTunes launch?
Apple stamps on next-gen Power Mac pics
Apple to slow annual OS X update rate

Mobile application security vulnerability report

More from The Register

next story
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
NUDE SNAPS AGENCY: NSA bods love 'showing off your saucy selfies'
Swapping other people's sexts is a fringe benefit, says Snowden
Own a Cisco modem or wireless gateway? It might be owned by someone else, too
Remote code exec in HTTP server hands kit to bad guys
British data cops: We need greater powers and more money
You want data butt kicking, we need bigger boots - ICO
Crooks fling banking Trojan at Japanese smut site fans
Wait - they're doing online banking with an unpatched Windows PC?
NIST told to grow a pair and kick NSA to the curb
Lrn2crypto, oversight panel tells US govt's algorithm bods
prev story

Whitepapers

Reducing security risks from open source software
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.