Tech ARP Forums

Go Back   Tech ARP Forums > Site Updates & Promotions > News
Register
FAQ Members List Calendar Arcade Mark Forums Read

Google Web www.techarp.com forums.techarp.com

News Post your comments about the top news posted at Adrian's Rojak Pot!

Reply
 
LinkBack Thread Tools
Old 17th Aug 2005, 09:36 AM   #1 (permalink)
Administrator!
 
Dashken's Avatar
 
Join Date: 21 Apr 2003
Location: Penang
Posts: 30,231
Reputation: 2352
Dashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond repute
Rep Power: 60
Default Apple unloads dozens of fixes for OS X!

Quote:
Apple Computer has released what seems to be one of its larger security updates for Mac OS X, doling out fixes for 44 flaws.

Still, only a handful of the vulnerabilities are of major concern, according to security analysts. The package of fixes was released Monday.

"This one is a big update. I don't recall seeing as many updates as we see today," said Thomas Kristensen, Secunia's chief technology officer.

By comparison, Apple last May released an update for 20 vulnerabilities and in March distributed an update for a dozen flaws.

But Kristensen noted that, with the new update, only a few of the 44 vulnerabilities are of great concern. He also said that 25 percent of the patches involve older vulnerabilities that have yet to lead to exploit code being developed by attackers. Still, Secunia is rating the overall update as "highly critical."

Apple declined to comment on the vulnerabilities and referred all questions to its security update.

The flaws affect Apple's Mac OS 10.3.9 and 10.4.2 operating system software and related server software.

Kristensen said that some vulnerabilities involving AppKit and Safari are critical.

AppKit, which is used to open RTFs (rich text files) and Word documents, has flaws that allow a remote attacker to create a malicious file that results in a buffer overflow. That in turn can lead to arbitrary code being executed on a user's system.

Apple, however, notes that only some applications use AppKit, and that Microsoft Word for Mac OS X is not vulnerable.

Flaws in Safari, meanwhile, can allow an attacker to bypass the browser's security checks and execute arbitrary commands, when the user clicks on a maliciously crafted rich text file.

Another flaw, a vulnerability in Apple's Sever Manager D, a modified version of Apache, is also being considered critical by some.

That flaw can result in a buffer overflow and remote execution of code by an attacker, with no user interaction, said Frank Nagle, assistant director of vulnerability aggregation for iDefense, a VeriSign company.

Although Apple lists other security flaws that could be exploited by a remote attacker, they are "less critical," according to Secunia.

For example, two vulnerabilities in Apache 2 could be exploited by a remote attacker to either bypass security restrictions or launch a denial-of-service attack.

But Apple did not set Apache 2 by default, so it is less of an issue than it would be if the same vulnerabilities affected Apache 1.3, Nagle said.

Source: http://news.com.com/Apple+unloads+do...3-5834873.html
__________________
| Intel Core 2 Duo E6850 @ 3.2Ghz | ASUS P5B-E Plus | G.SKILL 2x1GB DDR2 800 | 6 HDDs (2TB+ only ) | NVIDIA GeForce 7600GT | Dell E248WFP 24" Widescreen |

| Intel C2Q Q9450 | MSI P45 Neo3-FR | 2 x 2GB OCZ DDR2 PC2-6400 Gold Edition | 1 x Seagate 250GB HDD | 2 x Seagate 750GB HDD | 3 x Seagate 1TB HDD | NVIDIA GeForce 9500GT | Cooler Master CM690 chassis | Cooler Master eXtreme Power Plus 550W PSU | Dell E248WFP 24" Widescreen | Windows 7 Ultimate x64 |



Blog : Dashken's I-Blog
Gallery : Dashken's I-Paintings
Dashken is offline   Reply With Quote
SPONSOR

Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +8. The time now is 04:12 AM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Copyright © 1998-2009 Tech ARP. All rights reserved.