ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Desktop platforms Toolkit in association with http://ad.doubleclick.net/clk;205413468;14699245;m?http://adfarm.mediaplex.com/ad/ck/2397-58840-22058-14

Panther gets patched

Dawn Kawamoto CNET News.com

Published: 05 May 2005 10:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Apple on Tuesday released 20 patches for its OS X operating system designed to fix flaws that could catch users off-guard.

The vulnerabilities apply to Mac OS X 10.3.9 and Mac OS X Server 10.3.9, according to Apple's advisory. The announcement comes roughly a month after Apple issued nearly a dozen patches for Mac OS.

The advisory also falls just days after Apple's much ballyhooed release of the latest version of its operating system, Mac OS X 10.4, widely known as Tiger. The flaws were already addressed in Tiger, so the patches apply only to the previous version, known as Panther.

Security company Secunia on Wednesday rated Apple's OS X flaws as "highly critical". Among the flaws of greatest concern is a vulnerability in the OS X AppKit that relates to the handling of TIFF files.

"If people view a malicious TIFF, it could result in running arbitrary code," said Thomas Kristensen, chief technology officer for Secunia. "TIFF is usually viewed as safe form to view things, so this makes it more critical."

Another issue of concern is an AppleScript flaw. If users visit a Web site and accept AppleScript from that site, they could find it executing different code than they had expected, Kristensen added.

A flaw affecting the Apache Web server, meanwhile, could allow a buffer overflow in the htdigest program, which if used improperly in a CGI application could in turn allow a remote system attack.

Secunia downplayed the Apache flaw.

"Apache is an important bug fix, but it would be unusually difficult to exploit and it would need an unusual configuration," said Thomas Kristensen, chief technology officer for Secunia.

Two vulnerabilities were also found in the operating system's Bluetooth wireless capabilities. One could allow files to be shared without properly notifying the user, while another could be used by a malicious attacker to access files outside the default file exchange directory via the Bluetooth file and object exchange services.

Another flaw could allow directory services to be altered to give privileges to someone who is unauthorised to have them, according to the advisory.

Apple's OS X patch announcement also includes fixes for Finder, Foundation, Help Viewer, LDAP, libXpm, lukemftpd, NetInfo, Server Admin, sudo, Terminal and VPN.

Apple has no fixed schedule for issuing patches. By contrast, Microsoft in late 2003 moved to a monthly release of security fixes, and Oracle has adopted a similar practice, but on a quarterly basis.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
52 out of 117 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

IMMEDIATE DESKTOP SUPPORT VACANCY-1st & 2nd Line- LONDON- 22k

You will need a good understanding of Microsoft products such as Office, Windows (XP) 2003 environment, email such as Exchange and/or Active ...

MAC and PC support Contract Central London

My Client based in central London is currently looking for a candidate with a good mix of PC and Mac support. You will be required to support a ...

IT Systems Manager East Midlands

For this role you must be experienced in Exchange Server 2007, Active Directory domain management, network support, design and implementation of ...

Featured Talkback

So if you upgrade to XP SP3 you can't uninstall Internet Explorer, I'm quite sure I'm having a Deja-vu feeling about MS preventing people from uninstalling Internet Explorer in other Windows products.

By: TheKLF99

Read full story:
Upgraders to XP SP3 warned over IE downgrades

Desktop Management Benchmarking

Test Your Desktop Management Systems

How good are your company's desktop management solutions? How do they compare with those of your peers?

Take two minutes to complete our new Desktop Management and Energy Consumption benchmark, and find out what issues your business needs to focus on.