Feeds

Apple patches more than a dozen holes in OS X

Five uber updates in as many months

Choosing a cloud hosting partner with confidence

Apple has released an update that patches more than a dozen OS X vulnerabilities, several of which can lead to the remote execution of malicious code.

The most serious vulnerability resides in an OS X feature called mDNSResponder, which enables computers to locate and connect to devices such as printers and webcams on a local network. An attacker could use it to execute code by sending malicious packets to Macs connected to the same subnet, making the exploit ideal for use in internet cafes and offices.

Code exploiting the vulnerability has already been circulated by Immunity, a company that provides intelligence to security providers, according to Immunity's CTO, Dave Aitel.

"Remote roots like this don't come out every day," he said of the vulnerability.

Apple credited Michael Lynn of Juniper Networks for reporting the vulnerability. Lynn was the Cisco security researcher whose bosses threatened him with legal action in 2005 after publicly discussing vulnerability details in Cisco routers.

Yesterday's update was the fifth time in as many months that Apple has released to patch multiple security holes in its software. Apple has released other security patches this year, most recently to fix a high-profile vulnerability in QuickTime that allowed a hacker in a contest to publicly hijack a brand new MacBook Pro.

Among the other serious holes plugged in yesterday's update is flaw in OS X's CoreGraphics. That vulnerability could allow attackers to run code on a victim's machine by enticing users to open a maliciously crafted PDF file. ®

Beginner's guide to SSL certificates

More from The Register

next story
Xperia Z3: Crikey, Sony – ANOTHER flagship phondleslab?
The Fourth Amendment... and it IS better
Ex-US Navy fighter pilot MIT prof: Drones beat humans - I should know
'Missy' Cummings on UAVs, smartcars and dying from boredom
Don't wait for that big iPad, order a NEXUS 9 instead, industry little bird says
Google said to debut next big slab, Android L ahead of Apple event
Microsoft to enter the STRUGGLE of the HUMAN WRIST
It's not just a thumb war, it's total digit war
Netscape Navigator - the browser that started it all - turns 20
It was 20 years ago today, Marc Andreeesen taught the band to play
A drone of one's own: Reg buyers' guide for UAV fanciers
Hardware: Check. Software: Huh? Licence: Licence...?
The Apple launch AS IT HAPPENED: Totally SERIOUS coverage, not for haters
Fandroids, Windows Phone fringe-oids – you wouldn't understand
Apple SILENCES Bose, YANKS headphones from stores
The, er, Beats go on after noise-cancelling spat
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.