[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Apple Patch Fixes 18 Flaws In Mac OS X
http://www.crn.com/security/219100321;jsessionid=KJVF154WC5HBZQE
1GHRSKHWATMY32JVN
Apple (NSDQ:AAPL) released a security update Wednesday,
repairing 18 holes in its Mac OS X operating system, including
several critical imaging errors that enabled hackers to take
over victims' computers when they view a maliciously crafted
image file.
The Apple update, which upgrades the Mac OS X platform to
10.5.8, repaired an array of imaging flaws, as well as
vulnerabilities affecting the Safari Web browser. The flaws
paved the way for hackers to launch malicious code remotely on
users' computers.
Altogether, Apple plugged five holes in the way ImageIO
Framework -- an application designed to help Mac applications
read and write popular image formats -- handles OpenEXR files,
EXIF metadata and PNG images. Other image flaws included a patch
that resolved two heap buffer overflow vulnerabilities: one in
the way ColorSync, a color management interface, handles an
embedded profile; and the other in the way that ImageRAW handles
a Canon (NYSE:CAJ) RAW image file.
If left unpatched, hackers could launch attacks by enticing a
user to open a malicious image file -- usually through some
social engineering scheme -- which would subsequently download
information-stealing malware onto the user's system.
The patch also plugged a critical flaw affecting Apple's Safari
Web browser, occurring in CFNetwork, which allows hackers to
direct victims to a malicious Web site while the original Web
site URL remains displayed along with a certificate of warning.
Apple also repaired two networking vulnerabilities, one of which
could lead to remote code execution or a system crash if a user
opened a malicious AppleTalk response packet.
Included in the patch bundle was a fix for a heap buffer
overflow vulnerability in the XQuery component, which could lead
to remote execution by processing maliciously crafted XML
content.
Apple also fixed slightly less severe vulnerabilities in its
launchd services, which could lead to a denial of service attack
by opening numerous connections in launchd services, as well as
a logic bug in MobileMe, which could fail to delete all
credentials once a user logged out.