Apple Releases Mac OS X Security Patches
Although dated on the cusp of September, Security Update 2004-09-30 was actually released Monday in the first full week of October. The update spans Mac OS X 2.8 and greater; Mac OS X 10.3.5, released in August, is the latest version.
The patches were offered through Apples automatic Software Update service as well as from its download page.
The company identified some eight vulnerabilities in its latest patch release. Here is a rundown of the security fixes:
Click here to read about exploits of the Windows JPEG file vulnerability.
The NetInfo Manager issue, found only in OS X 10.3 systems, was subtle but could prove problematic to some IT managers. The utility software can enable root access to the machine, but after logging in as root, the software couldnt disable the access, even though the account appeared to be disabled.
Mac IT managers reported no early trouble installing the update.
"Most of these [vulnerabilities] are exploitable, but only in the most strange and bizarre sense," said Ron Hipschman, senior media specialist at San Franciscos Exploratorium science museum. While he said he is glad for the fixes, he didnt expect them to be readily exploited by attackers. "Youd have to be a real script kiddie to do so."
Check out eWEEK.coms Macintosh Center for the latest news, reviews and analysis about Apple in the enterprise. And for insights on Macintosh coverage around the Web, check out eWEEK.com Executive Editor Matthew Rothenbergs Weblog.

Be sure to add our eWEEK.com Macintosh news feed to your RSS newsreader or My Yahoo page
