10 Jun 2005
Apple has released a security update that fixes 11 vulnerabilities in the OS X operating system. The patched vulnerabilities include holes in both OS X Panther 10.3 and OS X Tiger 10.4.
While most of the repairs target arbitrary vulnerabilities, such as a way to circumvent a check for unsafe file formats by changing a file name, others represent more serious holes that could allow buffer overflow attacks or give hackers root access.
One of the vulnerabilities allowed devices using a Bluetooth connection to access files outside the default file exchange directory, Apple said on its website.
Another hole affecting both versions of the operating system was caused by multiple flaws in the PHP scripting language. The vulnerabilities could allow for remote denial of service attacks and the execution of arbitrary code.
The update also plugs some holes unique to OS X 10.4, including a vulnerability in the AFP server that was susceptible to a buffer overflow attack after which arbitrary code could be executed. The AFP server allows Windows computers to access files on a Mac through a network.
Another OS X 10.4 hole in CoreGraphics allowed console users to gain root access that could allow unprivileged users to launch commands.
Lastly, the patch fixes an error that gives users root access if a computer is used as a virtual private network server. The flaw could be exploited remotely through the internet. The same hole affected OS X 10.3.9, but was fixed last May.
Separate patches for OS X 10.3.9 and OS X 10.4.1 are available for download through the Apple Software Update service or online here.
Latest stories from Operating Systems
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
V3 examines the key strengths and weaknesses of Samsung's latest iPhone killer
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
C#, WPF, Silverlight, UI Development, Software Engineers...
Candidate required who is used to working in a client...
Build Change Release Manager / Build Change Manager...
IT Service Desk Manager / Liverpool / Up to £60,000...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?