All the latest UK technology news, reviews and analysis

Apple issues 13 security fixes

by Shaun Nichols

More from this author

25 May 2007

Be the first to comment

  • Tweet this
Apple worm
A flaw in the OS X CoreGraphics component is the most serious

Apple has issued security fixes for 13 components of its OS X operating system. 

A flaw in the OS X CoreGraphics component is the most serious, as it could allow an attacker to remotely execute code through a specially-crafted PDF file. The vulnerability only affects OS X 10.4.9 and OS X Server 10.4.9.

Apple did not say whether the code execution is confined to the limited privileges of the current user, or whether attackers could execute code at the root level.

Attackers could also target OS X's 'file' for remote code execution. This vulnerability affects all versions of Mac OS X 10.3 and 10.4. No other components suffered from remote execution vulnerabilities.

A flaw in Fetchmail could allow attackers to steal a user's email password. Fetchmail is used to download emails into a user's local machine, and Apple said that the component may not adequately encrypt the password.

Vulnerabilities in Apple's iChat messaging software and mDNSResponder were also patched. Both vulnerabilities could be exploited to remotely execute code, but would require the attacker to be on a local network with the target machine.

Apple also fixed a vulnerability in the way that OS X handles disk images. By convincing a user to mount two identically-named disk images, an attacker could disguise a piece of malicious software as a legitimate application or document.

The security update is available through Apple's software update system component or as a download from the company's website.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

98%

0%

1%

0%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Business Development / Account Manager (Unified Communications)

Business Development / Account Manager (Unified Communications...

Senior Software Engineer/Network Planner

Senior Software Engineer/Network Planner Sky Network...

Cisco Field Support Engineer (CCNA, CNVP, VoIP) to £45K

Cisco Field Support Engineer (CCNA, CNVP, VoIP) to £45K...

LAMP Developer with added class {PureClass}

LAMP Developer with added class {PureClass} Are you...

To send to more than one email address, simply separate each address with a comma.