Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Apple releases Security Update 2006-008 for OS X.4.8
Apple Computer ^ | 12/19/2006 | Apple Computer

Posted on 12/20/2006 2:31:16 AM PST by Swordmaker

About Security Update 2006-008

This document describes Security Update 2006-008, which can be downloaded and installed via Software Update preferences, or from Apple Downloads.

For the protection of our customers, Apple does not disclose, discuss, or confirm security issues until a full investigation has occurred and any necessary patches or releases are available. To learn more about Apple Product Security, see the Apple Product Security website.

For information about the Apple Product Security PGP Key, see "How to use the Apple Product Security PGP Key."

Where possible, CVE IDs are used to reference the vulnerabilities for further information.

To learn about other Security Updates, see "Apple Security Updates."

Security Update 2006-008

  • QuickTime for Java, Quartz Composer

    CVE-ID: CVE-2006-5681

    Available for: Mac OS X v10.4.8, Mac OS X Server v10.4.8

    Impact: Visiting a malicious web site may lead to information disclosure

    Description: Java applets may use QuickTime for Java to obtain the images rendered on screen by embedded QuickTime objects and upload them to the originating web site. When this facility is used in conjunction with Quartz Composer, it becomes possible to capture images that may contain local information. This update addresses the issue by disallowing Quartz Composer compositions in unsigned Java applets. Quartz Composer compositions continue to function locally. Applications and signed Java applets that utilize QuickTime and QuickTime for Java are unaffected. This issue does not affect systems prior to Mac OS X v10.4. It also does not affect the Windows platform. Credit to Geoff Beier for reporting this issue.



TOPICS: Computers/Internet
KEYWORDS:

1 posted on 12/20/2006 2:31:19 AM PST by Swordmaker
[ Post Reply | Private Reply | View Replies]

To: 1234; 6SJ7; Action-America; af_vet_rr; afnamvet; Alexander Rubin; anonymous_user; ...
Time to select Software Update under the Big Blue Apple on the Menu bar.

Security Update 2006-008 for OS X.4.8 PING!

If you want on or off the Mac Ping List, Freepmail me.

2 posted on 12/20/2006 2:32:56 AM PST by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Got it installed.

Thanks.


3 posted on 12/20/2006 6:34:40 AM PST by Sundog (Time flies like an arrow. Fruit flies like a banana.)
[ Post Reply | Private Reply | To 2 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson