Advertisement
Promo

Security threats Toolkit

Apple fixes Bind exploit and Safari bugs

Matthew Broersma ZDNet.co.uk

Published: 13 Aug 2009 16:16 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Apple has released fixes for a zero-day security hole in its products caused by an underlying flaw in the Bind internet server standard.

The Apple Bind patch addresses an issue that began being exploited in the wild last month, which could enable a remote attacker to crash servers that are masters of one or more zones. Security experts have warned that the Bind flaw is easily exploited.

In its advisory on Wednesday, Apple noted that Bind is included with Mac OS X and Mac OS X Server, but is not enabled by default. The update issued by Apple allows Mac OS X and Mac OS X Server to properly reject maliciously crafted messages, the company said. The versions affected are: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.8 and Mac OS X Server v10.5.8.

Separately on Tuesday, Apple patched a series of bugs in Safari, including flaws in CoreGraphics, ImageIO and WebKit that could allow an attacker to compromise a system.

The Safari patches are available for Microsoft Windows XP and Vista, as well as Mac OS X and OS X Server. One patch addresses a bug that could allow a malicious website to promote itself to Safari's Top Sites view.

Independent security firm Secunia ranked the most serious of the Safari bugs as "highly critical".

The WebKit update patches a flaw that could allow the disclosure of sensitive information and an error that could allow the use of lookalike characters in a URL to disguise the true address of a website.

Apple's last update to Safari was last week, on 5 August, as part of a general update to Mac OS X. The update patched 18 bugs.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
5 out of 5 people found this useful


Full Talkback thread

1 comment

  1. See.. CA

Company/Topic Alerts

Create a new alert from the list below:










Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters