[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Apple Patch Fixes 18 Flaws In Mac OS X



http://www.crn.com/security/219100321;jsessionid=KJVF154WC5HBZQE
1GHRSKHWATMY32JVN

Apple (NSDQ:AAPL) released a security update Wednesday, 
repairing 18 holes in its Mac OS X operating system, including 
several critical imaging errors that enabled hackers to take 
over victims' computers when they view a maliciously crafted 
image file.

The Apple update, which upgrades the Mac OS X platform to 
10.5.8, repaired an array of imaging flaws, as well as 
vulnerabilities affecting the Safari Web browser. The flaws 
paved the way for hackers to launch malicious code remotely on 
users' computers.

Altogether, Apple plugged five holes in the way ImageIO 
Framework -- an application designed to help Mac applications 
read and write popular image formats -- handles OpenEXR files, 
EXIF metadata and PNG images. Other image flaws included a patch 
that resolved two heap buffer overflow vulnerabilities: one in 
the way ColorSync, a color management interface, handles an 
embedded profile; and the other in the way that ImageRAW handles 
a Canon (NYSE:CAJ) RAW image file.

If left unpatched, hackers could launch attacks by enticing a 
user to open a malicious image file -- usually through some 
social engineering scheme -- which would subsequently download 
information-stealing malware onto the user's system.

The patch also plugged a critical flaw affecting Apple's Safari 
Web browser, occurring in CFNetwork, which allows hackers to 
direct victims to a malicious Web site while the original Web 
site URL remains displayed along with a certificate of warning.

Apple also repaired two networking vulnerabilities, one of which 
could lead to remote code execution or a system crash if a user 
opened a malicious AppleTalk response packet.

Included in the patch bundle was a fix for a heap buffer 
overflow vulnerability in the XQuery component, which could lead 
to remote execution by processing maliciously crafted XML 
content.

Apple also fixed slightly less severe vulnerabilities in its 
launchd services, which could lead to a denial of service attack 
by opening numerous connections in launchd services, as well as 
a logic bug in MobileMe, which could fail to delete all 
credentials once a user logged out.