All the latest UK technology news, reviews and analysis

Apple plugs ten 'critical' security holes

by Tom Sanders in California

23 Sep 2005

Comment: 1

  • Tweet this
Apple
Buffer overflow vulnerabilities could allow an attacker to take control

Apple has released a security update for its OS X 10.3 and OS X 10.4 operating systems.

The patch fixes vulnerabilities in the operating system itself as well as bundled applications.

Apple does not provide severity ratings for the flaws in its software, but an advisory from security website Secunia gave the vulnerabilities its second highest rating of 'highly critical'. 

The patch repairs a buffer overflow vulnerability in ImageIO, a Java tool used to display images. The security hole could allow an attacker to take control of a system by placing a specially crafted Gif image on a website.

Apple's Quickdraw manager is also susceptible to a buffer overflow attack through the use of a specially crafted Pict image. The tool is used by several applications, including Safari, Mail and Finder.

Other vulnerabilities patched in the update include Apple's Mail application, the Safari browser and the Quicktime Media player.

Mimicking Microsoft's 'patch Tuesday' release cycle, Apple usually releases security updates at midnight on the second Tuesday of the month.

This cycle is not official policy, however, and this month the vendor released its patch nine days later.

Microsoft did not release any patches in September, pulling a previously announced critical update because of "quality concerns".

Users can download the 7.1Mb Apple patch through the software update feature in the operating system or from the Apple website here

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Java Developer - Belfast - Banking

Java Developer - Belfast - Banking Skills: Core Java...

Shared Accounting Service Manager - London

I am recruiting for a Shared Accounting Service Manager...

QA Tester/Automation Tester - C# .NET Agile, Epsom

QA Tester/Automation Tester - C# .NET Agile, Epsom, Surrey...

3RD LINE EXCHANGE 2010 / 2003, QUEST, LONDON, BLUE CHIP FIRM, CITY

3RD LINE EXCHANGE 2010 / 2003, QUEST, LONDON, GLOBAL...

To send to more than one email address, simply separate each address with a comma.