ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Desktop platforms Toolkit in association with http://ad.doubleclick.net/clk;205413468;14699245;m?http://adfarm.mediaplex.com/ad/ck/2397-58840-22058-14

Apple fixes serious OS X flaws

Joris Evers CNET News.com

Published: 02 Mar 2006 08:50 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Apple on Wednesday released a security update for Mac OS X that fixes 20 vulnerabilities, including a high-profile Web browser and Mail flaw disclosed last week.

The set of patches addresses a variety of security flaws, including several that could let an attacker gain control over a computer running OS X. The patch arrives after two weeks of intense scrutiny for OS X safety, prompted by the discovery of two worms and the disclosure of two security flaws in that period.

The Apple security update addresses those flaws, which affect the Safari Web browser and Apple Mail client. The vulnerabilities expose Mac users to risks that are more familiar to Windows owners: the installation of malicious code through a bad Web site or email because of improper validation of downloads.

The update also changes iChat, Apple's instant messaging application, to thwart instant message threats such as the Leap.A pest, which was detected recently and attacked some Apple users.

"iChat now uses Download Validation to warn of unknown or unsafe file types during file transfers," Apple said.

Aside from the previously disclosed vulnerability in Safari, the Apple patch fixes four additional security bugs. These could result in code being executed on the user's machine after viewing a malicious Web site or allow JavaScript to execute in the local domain, Apple said in its update.

Other flaws fixed in the update include four issues related to the PHP scripted programming language, two problems related to Apple's Directory Services, a problem with mounting of file servers and a bug in FileVault secure storage, which was found to be insecure in the way a FileVault image is created.

Security Update 2006-001, can be downloaded and installed via the Software Update feature in Mac OS X or from Apple Downloads.

"Apple advises Mac OS X users to keep their system current by installing this and all Mac OS X software updates," Apple said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
68 out of 128 people found this useful


Company/Topic Alerts

Create a new alert from the list below:












Related Jobs

Solaris Support Analyst Surrey - 35,000

Experience with Perl, PHP, LDAP and Cisco would be of advantage but not essential. Ideally you will have experience in a similar role to the both as ...

Business Analyst ( OO , Java ) - London

Primary Responsibilities - Work with Financial Engineers and Developers to conduct sophisticated validation of existing and new models; develop test ...

Technical Designer - Oxfordshire

Moreover, the role is as much about enhancing and formulating new processes as it is about technical design and validation. RM has an exciting ...

Featured Talkback

So if you upgrade to XP SP3 you can't uninstall Internet Explorer, I'm quite sure I'm having a Deja-vu feeling about MS preventing people from uninstalling Internet Explorer in other Windows products.

By: TheKLF99

Read full story:
Upgraders to XP SP3 warned over IE downgrades

Desktop Management Benchmarking

Test Your Desktop Management Systems

How good are your company's desktop management solutions? How do they compare with those of your peers?

Take two minutes to complete our new Desktop Management and Energy Consumption benchmark, and find out what issues your business needs to focus on.