Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

(Apple) Security Update fixes Finder, iChat, more
MacNN ^ | 02/15/2007

Posted on 02/15/2007 4:42:57 PM PST by JohnSheppard

Apple today released Security Update 2007-002 to fix several vulnerabilities affecting the Mac OS X Finder, iChat, and the UserNotificationCenter process. One vulnerability could cause an application to crash or result in arbitrary code execution, resuming the user is enticed into opening a specially-crafted disk image resulting in a buffer overflow in Finder's handling of volume names. Two iChat-related security concerns are fixed in the update, preventing attackers on the local network from causing iChat to crash and foiling potential attempts by malicious websites to cause applications to crash or execute arbitrary code. The UserNotificationCenter process runs with elevated privileges in the context of local users, potentially allowing a malicious local user to overwrite or modify system files prior to the update. The update is available for download from Apple's website, as well as via the "Software Update" feature in Mac OS X located under the Apple menu.

(Excerpt) Read more at macnn.com ...


TOPICS: Computers/Internet
KEYWORDS: apple; osx; securityupdate
Navigation: use the links below to view more comments.
first 1-2021-22 next last
Also, in Software Update:

Apple offers Java, daylight savings updates

Apple today updated the way Mac OS X handles Daylight Saving Time for Tiger (and DST for Mac OS X 10.3 Panther) and updated Java for Mac OS X 10.4 (and Java for Mac OS X 10.3 Panther) to add support for those same changes. The Daylight Saving Time update reflects changes in several countries and regions that will alter the dates on which they observe Daylight Saving Time, while the Java for Mac OS X 10.4 Release 5 adds support for the latest Daylight Saving Time changes and time zone information. The Java update also provides improved reliability and compatibility for Java 2 Platform Standard Edition 5.0 and Java 1.4 on Mac OS X 10.4.8 and later. The release updates J2SE 5.0 to version 1.5.0_07 and Java 1.4 to version 1.4.2_12, improving reliability of the SWT_AWT bridge implementation first released in the SWT Compatibility Libraries for Release 4. The improvement is installed as a standard part of J2SE 5.0, according to Apple.

1 posted on 02/15/2007 4:42:58 PM PST by JohnSheppard
[ Post Reply | Private Reply | View Replies]

To: Swordmaker

Apple ping


2 posted on 02/15/2007 4:44:18 PM PST by JohnSheppard
[ Post Reply | Private Reply | To 1 | View Replies]

To: JohnSheppard

so many bugz, so little fixes...


3 posted on 02/15/2007 4:49:06 PM PST by Echo Talon
[ Post Reply | Private Reply | To 1 | View Replies]

To: JohnSheppard

But we've all been told that Apple has no need for fixes.


4 posted on 02/15/2007 4:50:44 PM PST by TommyDale (What will Rudy do in the War on Terror? Implement gun control on insurgents and Al Qaeda?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: TommyDale
But we've all been told that Apple has no need for fixes.

Even Moses used "Wite-Out" ;) LOL


5 posted on 02/15/2007 4:59:48 PM PST by Echo Talon
[ Post Reply | Private Reply | To 4 | View Replies]

To: 1234; 6SJ7; Abundy; Action-America; af_vet_rr; afnamvet; Alexander Rubin; anonymous_user; ...
Mac Update PING!

Security

Java

Daylight Savings Time change

If you want on or off the Mac Ping List, Freepmail me.

6 posted on 02/15/2007 5:51:14 PM PST by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: TommyDale
But we've all been told that Apple has no need for fixes.

No one has ever said that on FreeRepublic... or on any of the Apple forums that I have read (lots). It is a strawman usually stated by Windows fans.

7 posted on 02/15/2007 5:53:36 PM PST by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE!)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Swordmaker

Thanks for the ping!


8 posted on 02/15/2007 6:20:02 PM PST by vox_freedom (Matthew 5:37 But let your speech be yea, yea: no, no)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Swordmaker
Thank you! My, this Apple ping list is a schmanzy thing!!
9 posted on 02/15/2007 6:21:41 PM PST by blu (All grammar and punctuation rules are *OFF* for the "24" thread.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: blu

and...it is FREE!!

I just love the friendly banter amongst the various factions!

What are we supposed to do when we're running BOTH XP and Mac?


10 posted on 02/15/2007 6:25:36 PM PST by GRRRRR ( What's Next? - Daytona 500 & Spring Training!)
[ Post Reply | Private Reply | To 9 | View Replies]

To: GRRRRR
What are we supposed to do when we're running BOTH XP and Mac?

Just make sure PC Guy plays nice with Mac Guy!

11 posted on 02/15/2007 6:30:48 PM PST by blu (All grammar and punctuation rules are *OFF* for the "24" thread.)
[ Post Reply | Private Reply | To 10 | View Replies]

To: JohnSheppard

For all you Mac users out there... don't worry about this. Security vulnerabilities only happen on PC's. No need to update.


12 posted on 02/15/2007 6:34:35 PM PST by Ramius ([sip])
[ Post Reply | Private Reply | To 1 | View Replies]

To: GRRRRR
What are we supposed to do when we're running BOTH XP and Mac?

If they are both on a Mac, I understand there might be a problem with the clocks. Because of the ways each system handles the system clock, I believe you have to wait for the PC to reset the clock after rebooting with Boot Camp... and vice-verse into the Mac. The Mac checks the clock on boot up. The PC apparently doesn't but instead does it on a schedule something like every half hour. Parallels will use the Mac clock.

Microsoft will have an update for handling the political driven change in daylight savings time. I wonder if MS will update W98, W2000, WME, etc.

13 posted on 02/15/2007 6:39:02 PM PST by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE!)
[ Post Reply | Private Reply | To 10 | View Replies]

To: Ramius
Security vulnerabilities only happen on PC's. No need to update.

Vulnerabilities occur on both systems... but so far only PCs have in-the-wild exploits of those vulnerabilities.

14 posted on 02/15/2007 6:40:51 PM PST by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE!)
[ Post Reply | Private Reply | To 12 | View Replies]

To: Swordmaker

Yah. Ok.

I actually don't have a dog in this fight. I'm a big fan and user of Windows, Mac, Linux, Unix and a little VMS. They've all got their good and bad points and they've each got their place in the enterprise.

But what cracks me up are the mac users that continue to live in a totally pants-down dreamland of invulnerability. The inevitability of the eventual reality check will be difficult not to pounce on with much mirth and celebration.

But I was a machead first. So it is with sadness, too.

:-)


15 posted on 02/15/2007 6:50:02 PM PST by Ramius ([sip])
[ Post Reply | Private Reply | To 14 | View Replies]

To: Swordmaker

There's been patches out for the DST clock thing for months for at least Windows 2000 and up. I haven't checked about W98 or prior since I don't have any users on those antiques.

But then again, Apple doesn't have a DST patch for System 6 or 7, either.


16 posted on 02/15/2007 6:53:43 PM PST by Ramius ([sip])
[ Post Reply | Private Reply | To 13 | View Replies]

To: TommyDale
But we've all been told that Apple has no need for fixes.

Please do us all a favor and find that post.

We'll wait. 

17 posted on 02/15/2007 9:17:11 PM PST by zeugma (MS Vista has detected your mouse has moved, Cancel or Allow?)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Ramius
For all you Mac users out there... don't worry about this. Security vulnerabilities only happen on PC's. No need to update.

I'm sure we'd all like to see that post as well.

Don't worry, we'll wait.


 

18 posted on 02/15/2007 9:20:47 PM PST by zeugma (MS Vista has detected your mouse has moved, Cancel or Allow?)
[ Post Reply | Private Reply | To 12 | View Replies]

To: zeugma

It's on all the commercials, dude...


19 posted on 02/15/2007 9:23:29 PM PST by Ramius ([sip])
[ Post Reply | Private Reply | To 18 | View Replies]

To: JohnSheppard
I wish they'd taken the time to rework how daylight savings is handled. There is no reason whatsoever that I can find for this to be more than just an updated text file that contains the start/stop dates of daylight savings time for applicable locales.

Most Unix systems actually run the system clock as GMT,  with the time you are displayed being an offset from GMT based on an environment variable or a localization configuration file. This is why you can have Alice in San Diego and Bob in Dallas, and Charlie in Orlando login to the same system, and each have their local time displayed to them (providing, of course they have their TZ environment variable set, as should be the case if you have folks from across the country, or world logging into one system.

Why not just have the start/stop date and offset in a file so folks wouln't have to worry as much the next time the idiots in Washington decide they know better than God does about what time the sun should rise and set. Sometimes the arrogance of the criminals that populate that city astounds me. To protect ourselves from future declarations against nature, we should make it as easy as possible to deal with their lunacy.

20 posted on 02/15/2007 9:57:20 PM PST by zeugma (MS Vista has detected your mouse has moved, Cancel or Allow?)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-22 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson