Safari Flaws Fixed in Monster Mac OS X Update

執筆者
Ryan Naraine
Ryan Naraine
Published: Aug 16, 2005
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Apple has shipped a monster security patch for Mac OS X to fix 34 flaws in the operating system and bundled third-party utilities.

The 17MB security update, available through Software Update and Apple Downloads, corrects a wide range of flaws in Mac OS X 10.3.9 (client and server).

Security alerts aggregator Secunia Inc. rated the update as “highly critical” and warned that Mac users are at risk of security bypass, cross-site scripting, data manipulation, data leakage, privilege escalation, denial-of-service and system access attacks.

The update includes two fixes for bugs in the default Safari Web browser that could allow phishing attacks.

/zimages/1/28571.gifRead morehereabout recent buffer-overflow patches for Apples Tiger OS.

According to Apple Computer Inc., one of the Safari flaws could lead to the execution of arbitrary commands if a user clicks on a maliciously crafted rich text file from the browser.

“Safari renders rich text content using code that allows URLs to be called directly, which bypasses the normal browser security checks,” the company said.

Another Safari flaw could allow information to be inadvertently submitted to the wrong site. “When submitting forms in Safari on an XSL-formatted page, data is sent to the next page browsed,” Apple explained, noting that the update ensures the information is submitted correctly.

Three vulnerabilities in Apples implementation of the open-source Apache server are also addressed, including a buffer overflow in the “htdigest” program that could allow remote system compromise.

Another three flaws in “AppKit” are also addressed to correct buffer overflows in the way rich text files are handled. A separate buffer overrun could also allow the execution of arbitrary code when Word documents are read.

Apple also fixed three flaws in the Kerberos network authentication protocol, including one that could lead to system compromise.

“A heap buffer overflow in password history handling code could be exploited to execute arbitrary code on a Key Distribution Center (KDC). This issue does not affect Mac OS X 10.4,” the company said.

Advertisement

/zimages/1/28571.gifAn Apple “mega patch” plugs 20 holes in Mac OS X.Click hereto read more.

The patch also includes fixes for multiple Kerberos buffer overflow vulnerabilities that could result in denial-of-service or remote compromise of a KDC.

The update also includes security patches for flaws in Bluetooth, CoreFoundation, CUPS, Directory Services, HItoolbox, loginwindow, Mail, MySQL, OpenSSL, ping, QuartzComposerScreenSaver, SecurityInterface, servermgrd, servermgr_ipfilter, SquirrelMail, traceroute, WebKit, Weblog Server, X11 and zlib.

/zimages/1/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

Ryan Naraine

Ryan Naraine

Content Writer

Ryan Naraine is a ServerWatch, eSecurity Planet, and eWEEK contributor.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。