All the latest UK technology news, reviews and analysis

Apple OS X update plugs 20 security holes

by Tom Sanders in California

02 Mar 2006

Comments: 2

  • Tweet this
Malware writers have released several high profile viruses aimed at Mac OS X in recent weeks
Apple's latest update fixes the recent Leap-A and Safari security vulnerabilities in Mac OS X

Apple has released a security update that patches 20 holes in its OS X operating system and bundled applications. 

Malware writers have released several high profile viruses in recent weeks, and security experts disclosed last week that they had found a critical security hole in the operating system.

"The update fixes the recently reported Leap-A and Safari security vulnerabilities," an Apple spokesman told vnunet.com.

The Safari vulnerability was exposed last week by German researcher Michael Lehn. The flaw could allow an attacker to launch arbitrary code on a Mac computer running the Safari browser through the use of a specially crafted website. 

The Apple security update also contains a fix for a vulnerability in relation to the Safari flaw. It affects the way that the operating system unpacks and executes meta data in certain types of archives.

This could be exploited in combination with the Safari vulnerability or by persuading a user to open an email message containing a specially crafted archive file.

The update also changes some OS X security settings to protect users against worms such as Leap-A that were detected last month.

The worm spread through Apple's iChat instant messaging client by sending a file to the buddies in a user's contact list, warning users when they are downloading unknown or unsafe file types through the use of a feature called Download Validation.

The same feature is also used in the Mail application, but in this case attackers could disguise a file's type to bypass the security feature. The update closes this loophole.

Less severe vulnerabilities have also been repaired, such as a flaw in Directory Service that allows local users to create and manipulate files as a root user.

Attackers could have exploited another design flaw in the way that the software handled IPsec to launch a denial of service attack against virtual private networks.

Users can install the update through the auto update feature in the operating system or by downloading the patch from Apple's website here

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

98%

0%

1%

0%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Software Design Architect (Windows Database Application)

Software Design Architect (Windows Database Application...

Lead Java Developer - Mobile- Digital- Amsterdam

Lead Java Developer - Fast growing, young and international...

Graduate Software Support Engineer

Job Specification Graduate Support Engineer...

c# or asp.net Software Developer

Job Specification For: Software Developer...

To send to more than one email address, simply separate each address with a comma.