The Register®

Original URL: http://www.theregister.co.uk/2004/06/08/apple_os_x_patch/

Apple posts second Mac OS X vuln patch

Nabbed

By Tony Smith

Posted in Enterprise Security, 8th June 2004 11:45 GMT

Free whitepaper – Total cost of ownership of Dell, HP and IBM blade solutions

Update Apple has posted a second software update intended to fix a vulnerability that exploits the way Mac OS X handles URI links.

We installed the update, Security Update 2004-06-07, on a Mac OS X 10.3.4 machine. After restarting the machine, we went straight to Unsanity's web site, the location of a pair of web pages that test the URI vulnerability (http://www.unsanity.com/haxies/pa/whitepaper). Neither tests was blocked by the update, details of which can be found here (http://docs.info.apple.com/article.html?artnum=61798).

The same site provides Paranoid Android (http://www.unsanity.com/haxies/pa/), a utility that halts attempts to open apps from URIs and offers the user the choice of proceeding with the attempt or to cancel it.

Security Update 2004-06-07 does the same thin. We initially downloaded the update using Mac OS X's Software Update facility and we tried again using the download posted on Apple's web site.

Unlike Paranoid Android, the code contained in the update remembers applications the user has permitted other applications to open, or those that the user has opened themselves. So it's possible that the system is allowing access to the test site apps because they have already been run prior to the installation of the update.

Certainly a number of Register readers have told us the update works for them with both Unsanity tests.

We'd certainly recommend installing the new update in any case. ®

Related stories

Mac OS X update fails to fix vulnerability (http://www.theregister.co.uk/2004/05/28/mac_bug_mishandled/)
Apple posts Mac OS X update (http://www.theregister.co.uk/2004/05/27/apple_posts_1034/)
Apple patches critical Mac OS X hole (http://www.theregister.co.uk/2004/05/24/apple_fixes_osx_flaw/)
Apple picks 15 June for iTunes launch? (http://www.theregister.co.uk/2004/06/07/apple_itunes_launch/)
Apple stamps on next-gen Power Mac pics (http://www.theregister.co.uk/2004/06/07/apple_next_g5/)
Apple to slow annual OS X update rate (http://www.theregister.co.uk/2004/05/21/apple_osx_schedule/)