Feeds

Modest Apple update slices third-party bugs

Dirty dozen vulns pureed

Securing Web Applications Made Simple and Scalable

Apple has pushed out a major security update designed to crush a dozen security bugs, some of which present a critical security risk on unpatched systems. Many of the fixes involve flaws in third-party applications bundled with Mac OS X, rather the flaws in the OS itself.

Patches released by Apple on Tuesday address a malware injection risk in the CoreAudio media player, Flash Player plug-in bugs and a similarly critical vulnerability involving Image Raw. The update also tackles a recently discovered OpenSSL renegotiation exploit. Security fixes for CUPS and Image IO make up the remainder of the patch batch.

Andrew Storms, director of security operations for network security firm nCircle, described the size of the update as smaller than usual. The patch batch of six updates tackles 12 vulnerabilities, compared to the 40 odd bugs normally squashed by the fruit-themed consumer tech giant during a security update cycle.

"Most of these updates are connected with third party software. For example, seven of the twelve CVEs are connected with the update for Adobe's flash player plug-in," Storms said. "The remainder of the bugs patched today are the usual file format parsing problems that we've seen a lot of in the past."

An advisory from Apple (here) provides full details of the runners and riders contained in the update batch. Apple - unlike Microsoft, Adobe and Oracle - issues patch batches as and when they are needed rather than on a regular pre-announced monthly or quarterly schedule.

Bi-monthly updates from Apple are about par. Typically these updates are applied in the background and applied painlessly after Mac fans reboot their systems. ®

The smart choice: opportunity from uncertainty

More from The Register

next story
Mozilla fixes CRITICAL security holes in Firefox, urges v31 upgrade
Misc memory hazards 'could be exploited' - and guess what, one's a Javascript vuln
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
prev story

Whitepapers

Top three mobile application threats
Prevent sensitive data leakage over insecure channels or stolen mobile devices.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.