14 Apr 2011
Apple has released security updates for iOS, Safari and Mac OS X, including a patch to address a vulnerability in the SSL system caused by the security breach at Comodo last month.
A hacker used stolen data from Comodo to craft a series of fraudulent SSL certificates.
Apple said that the updates change its trust policy to recognise and block the fraudulent SSL certificates.
The update will be rolled out to iPhone, iPad and iPod Touch users running iOS 4.2 and 4.3, as well as OS X and the Mac and Windows versions of Safari.
Apple has also issued fixes for two flaws in the WebKit browser platform, which could be exploited by an attacker to perform a remote code execution attack.
The iOS 4.3.2 update also patches a remote code execution flaw in the QuickLook component and a possible data disclosure flaw in the libxslt software. A fix for the QuickLook vulnerability is also being included in the iOS 4.2.7 update.
iOS users can obtain the security fix by connecting the handset to iTunes via a Mac or PC connection. The Safari and OS X updates can be obtained through Apple's Software Update utility.
The release comes in a busy week for security patches. Microsoft released a record-breaking number of security fixes on Tuesday, while Adobe warned of a flaw in its Flash Player software which is being targeted in the wild.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Sneak peek at the forthcoming glass-based machine
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Skills: Open Source, C, C++, Java, Python, SQL, Developer...
ActionScript 3, Flex, Javascript, HTML, CSS, XML My...
My client is a real-time advertising and content 'start...
C++, UNIX, Multithreading My client is a leading software...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?