Advertisement
Promo

Security threats Toolkit

Apple issues critical fixes

Graeme Wearden ZDNet.co.uk

Published: 16 Aug 2005 15:00 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Apple has patched a number of security holes in its Panther and Tiger flavours of Mac OS X in its latest security update, released late on Monday.

Four patches were issued in total, covering the server and client versions of both Panther (Mac OS X 10.3.9) and Tiger (Mac OS X 10.4.2). The server patches address problems in 20 components, while the client patches fix 15 flaws.

According to security firm Secunia, more than 40 separate vulnerabilities are addressed in the four patches.

Several vulnerabilities that would allow attackers to cause a buffer overflows have been identified and fixed by Apple. One affected programs that use AppKit to open Microsoft Word documents. Another problem, which also affected Appkit, meant that a user who opened a specially crafted rich text file could allow malicious code to run on their machine.

Apple also changed the way Bluetooth connections were handled, eliminating a bug in the System Profiler that causes it to display misleading information about whether or not a Bluetooth device requires authentication.

The Safari Web browser has also been updated, fixing a flaw that could allow arbitrary command execution by clicking on a link in a maliciously crafted rich text file, and a bug that could mean Safari sent data to the wrong Web sites.

For more detail on the security flaws, and to download the patches, visit the Apple Web site.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
72 out of 149 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

4 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters