Mac OS X Update Swats Five Security Bugs

Mac OS X Update Swats Five Security Bugs

Écrit par
Ryan Naraine
Ryan Naraine
Nov 1, 2005
2 minute read
eWeek Le contenu et les recommandations de produits sont indépendants de la rédaction. Nous pouvons gagner de l'argent lorsque vous cliquez sur des liens vers nos partenaires. En savoir plus

Apple Computer Inc. late Monday shipped a security update to patch five Mac OS X security flaws and warned that the most dangerous bug could be exploited to bypass security restrictions.

In an advisory, Apple urged users to upgrade to Mac OS X 10.4.3 (client and server) to protect against security bypass and system exposure attacks.

The most serious of the five flaws is an error in “memberd,” the daemon process used by the system to resolve group memberships.

/zimages/3/28571.gifApple plugs Mac OS X Java holes.Click hereto read more.

In certain situations, Apple explained, changes to a groups membership may be delayed for hours in access control checks, resulting in an authenticated user being able to access files or other resources even after they have been removed from a group.

“This update addresses the issue by invalidating the group membership cache at appropriate times,” Apple said, noting this bug does not affect systems prior to Mac OS X v10.4.

The update also fixes an error in the Keychain access utility. The bug, which affects users of Mac OS X v10.4.2 and Mac OS X Server v10.4.2, causes a keychain to display passwords that are supposed to be stored and locked.

Several errors in the kernel that could allow the disclosure of memory to local users were also fixed. Apple said certain kernel interfaces may return data that includes sensitive information in uninitialized memory.

Two other flaws, in Finder and in Software Update, were also addressed.

Patch download locations have been included in the Apple advisory.

/zimages/3/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Propriété de TechnologyAdvice. © 2026 TechnologyAdvice. Tous droits réservés

Divulgation publicitaire : Certains des produits qui apparaissent sur ce site proviennent d'entreprises dont TechnologyAdvice reçoit une compensation. Cette compensation peut influencer la façon dont les produits apparaissent sur ce site, notamment l'ordre dans lequel ils apparaissent. TechnologyAdvice n'inclut pas toutes les entreprises ou tous les types de produits disponibles sur le marché.