Advertisement
Promo

Security threats Toolkit

Apple patches OS X

Joris Evers CNET News

Published: 29 Nov 2006 08:25 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Apple on Tuesday released a security update for Mac OS X to repair 31 vulnerabilities, including a zero-day Wi-Fi hijack flaw.

Apple's Security Update 2006-007 includes fixes for flaws in Apple's own code as well as third-party components that ship with the Mac OS X operating system, such as Perl, PHP and OpenSSL. Several of the vulnerabilities could allow full system compromises, according to Apple's security alert.

However, Apple's update does not address all publicly known flaws in the operating system. Over the past few weeks, bug hunters, as part of an initiative called the Month of the Kernel Bugs, have published details on several new vulnerabilities in Mac OS X. One of those was tagged "highly critical" by security-monitoring company Secunia.

"Apple hasn't fixed any of the bugs published during the Month of Kernel Bugs, except for the AirPort issue," said "LMH", the code name of the security researcher who started the Month of the Kernel Bugs. "Apple users are still exposed to any potential risks related to those unpatched issues."

The security hole in the AirPort driver software affects Macs that shipped with Apple's original AirPort card, Apple said. An attacker nearby the computer could commandeer a vulnerable system by sending it a malicious network packet, according to Apple's alert.

Other flaws addressed by the Apple update could let Macs be compromised through malicious sites, rigged compressed files or malicious font files, Apple said. The update also fixes four flaws in the Mac OS X Security Framework, the worst of which could crash Macs or display expired security certificates as still valid, Apple said.

The Security Update 2006-007 for Mac OS X client and server software is available from the Software Update pane in Mac OS System Preferences, or Apple's downloads website. Apple recommends Mac users install it.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
377 out of 466 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Climate research centre compromised

One of the UK's leading climate change research centres has had a security breach. The Climate Research Unit at the University of East Anglia (UEA) suffered a compromise of information,... More

1 comment

Government web-monitoring plans on hol...

Government plans to compel ISPs to process and store details of all web communications have been put on hold until after the next election. The Home Office told ZDNet UK on Wednesday... More

1 comment

Watchdog reveals illegal sale of phone...

The Information Commissioner's Office is preparing a prosecution file against a mobile operator's employees who allegedly sold on thousands of customers' details to a competitor. The... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters