Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Apple
    • Apple
    • Applications
    • Cybersecurity
    • Networking

    Apple Patch Day: 10 Holes Covered in Tiger, Leopard

    Written by

    Ryan Naraine
    Published February 11, 2008
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The Mac OS X security train pulled into the patching station Feb. 11 with fixes for a total of 10 vulnerabilities, including one that was first disclosed more than a year ago during the Month of Apple Bugs project.
      The megapatch-available for both Tiger and Leopard users-covers holes that put Mac users at risk of code execution, denial-of-service and information disclosure attacks. Eight of the 10 vulnerabilities affect Mac OS X 10.5.2.
      According to a security bulletin accompanying the patches, one of patches covers a security hole disclosed more than 11 months ago during the controversial MOAB project, in which hackers released daily alerts for flaws in the Mac ecosystem.
      The bug, described as a stack buffer overflow, exists in the SLP (Service Location Protocol) daemon, and can execute arbitrary code with system privileges.
      The patch batch also covers a serious flaw in the way the Safari browser handles certain URLs. “Accessing a maliciously crafted URL may lead to an application termination or arbitrary code execution,” Apple warned, chalking it up to a memory corruption issue. The vulnerability does not affect systems prior to Mac OS X v10.5.
      The Launch Services API, which is used to open applications or their document files or URLs in a way similar to the Finder or the Dock, is also being patched, in order to correct a bug that causes an application to be launched via Time Machine backup even after it’s removed from the system.

      Click here to read about a bug Apple plugged in QuickTime that could lead to “drive-by” malware installations.

      The Mac OS X Mail client is also being patched to fix an implementation issue in Mail’s handling of “file://” URLs. “[This could] allow arbitrary applications to be launched without warning when a user clicks a URL in a message,” Apple warned. The Security Update also covers a gaping hole in Samba that could lead to an unexpected application termination or arbitrary code execution. The issue is a stack buffer overflow in Samba when processing certain NetBIOS Name Service requests.
      “If a system is explicitly configured to allow ‘domain log-ons,’ an unexpected application termination or arbitrary code execution could occur when processing a request. Mac OS X Server systems configured as domain controllers are also affected,” Apple said.
      A separate patch also covers a Terminal hole that could allow code execution attacks from simply viewing a booby-trapped Web page. Apple described the issue as an input validation error in the processing of URL schemes handled by Terminal.app.
      Apple also patched a remote code execution issue in the way NFS (Network File System) handled mbuf chains; a pair of X11 vulnerabilities that introduce arbitrary code execution risks; and an information disclosure bug in Parental Controls.

      Ryan Naraine
      Ryan Naraine

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.