Advertisement
Promo

Security threats Toolkit

Apple issues critical fixes

Graeme Wearden ZDNet.co.uk

Published: 16 Aug 2005 15:00 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Apple has patched a number of security holes in its Panther and Tiger flavours of Mac OS X in its latest security update, released late on Monday.

Four patches were issued in total, covering the server and client versions of both Panther (Mac OS X 10.3.9) and Tiger (Mac OS X 10.4.2). The server patches address problems in 20 components, while the client patches fix 15 flaws.

According to security firm Secunia, more than 40 separate vulnerabilities are addressed in the four patches.

Several vulnerabilities that would allow attackers to cause a buffer overflows have been identified and fixed by Apple. One affected programs that use AppKit to open Microsoft Word documents. Another problem, which also affected Appkit, meant that a user who opened a specially crafted rich text file could allow malicious code to run on their machine.

Apple also changed the way Bluetooth connections were handled, eliminating a bug in the System Profiler that causes it to display misleading information about whether or not a Bluetooth device requires authentication.

The Safari Web browser has also been updated, fixing a flaw that could allow arbitrary command execution by clicking on a link in a maliciously crafted rich text file, and a bug that could mean Safari sent data to the wrong Web sites.

For more detail on the security flaws, and to download the patches, visit the Apple Web site.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
72 out of 148 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters