Feeds

Apple megapatch fixes multiple flaws

Fruity

Internet Security Threat Report 2014

Apple has released a security update to its Mac OS X operating systems to plug multiple security holes. Bugs in third-party components have also been addressed by the security update.

The availability of Mac OS X 10.4.9 and Security Update 2007-003 on Tuesday follows a month in which the security of the OS was put under the spotlight by the Month of Apple Bugs project, which took place in January and November's Month of Kernel Bugs.

Protection against most of these unpatched bugs was previously available only through unofficial updates or various workarounds.

The flaws covered security bugs in both Apple Mac OS X and Mac OS X Server versions 10.3.x and 10.4.x and carried a variety of risks, the most serious of which might have allowed hackers to inject hostile code onto vulnerable systems. Bypassing security restrictions or launching denial of service attacks was also possible as a result of the flaws, which affect both Intel-based and PowerPC-based Apple systems.

Various bugs in the way Mac OS X mounted disc images, memory corruption risks associated with opening maliciously constructed images, kernel bugs, a brace of flaws in the AppleTalk networking protocol, and a vulnerability involving printing, are among the highlights of the patch batch.

In fairness, there's been little or nothing by way of reports that suggested the flaws were the subject of active hacking attacks.

Many of the security fixes address vulnerabilities in products from other vendors that ship with Apple OS X or OS X Server, including bugs in Adobe Flash and OpenSSH.

The security updates can be either downloaded and installed via Software Update preferences, or directly from Apple Downloads as explained in a security advisory from Apple here. A summary of the update has been published by security clearing house US CERT here. ®

Internet Security Threat Report 2014

More from The Register

next story
George Clooney, WikiLeaks' lawyer wife hand out burner phones to wedding guests
Day 4: 'News'-papers STILL rammed with Clooney nuptials
Shellshock: 'Larger scale attack' on its way, warn securo-bods
Not just web servers under threat - though TENS of THOUSANDS have been hit
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
PEAK IPV4? Global IPv6 traffic is growing, DDoS dying, says Akamai
First time the cache network has seen drop in use of 32-bit-wide IP addresses
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
Stunned by Shellshock Bash bug? Patch all you can – or be punished
UK data watchdog rolls up its sleeves, polishes truncheon
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.