Apple releases bumper patch batch
DNS cache poisoning flaw finally fixed
Posted in Operating Systems, 16th September 2008 10:25 GMT
Webcast: Building Applications for the 21st Century
Apple has published a major security patch. Mac OS X 10.5.5 is the sixth substantial security update from the company this year. The patch cycle also includes fixes for version 10.4 of Apple's software.
Both updates mend DNS security holes in older versions of BIND previously bundled with Apple's software. There are also updates for Directory Services, kernel, OpenSSH remote access software, QuickDraw Manager and more.
The flaws in ImageIO, QuickDraw Manager, VideoConference and ATS could lend themselves to hostile code injection. Meanwhile security bugs in libresolv could allow DNS cache poisoning, Apple's security notice explains.
Security watchers - such as the Internet Storm Centre - recommend the prompt patching of Apple systems. The updates follow fixes for iTunes and QuickTime application software released last week. ®

The Register Guide to Extended Validation
LDAP Injection [3-2APZ1KL]
Blind SQL Injection [3-2APYM5E]
Preventing Google Hacking [3-2APYMGU]
Building Web Application Security into Your Development Process [3-2APYMBV]
Hidden recipes for OS X charts and graphs
Time to reject traditional database techniques?
Why clouds should be more like operating systems
Windows 7 early promise: Passes the Vista test