Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Apple Issues Megapatch of 25 Fixes
Newsfactor ^ | April 20, 2007 | Barry Levine

Posted on 04/20/2007 7:51:27 PM PDT by jdm

On Thursday, Apple issued a megapatch of bug-fixes for its Mac OS X desktop and OS X server systems. The fixes, 25 in all, are itemized in the company's Security Update 2007-004.

Apple recommended that all OS X users install the update. It said that the vulnerabilities could lead to a system crash or allow an intruder to run unauthorized software on the computer. The fixes relate to various components and services in the Mac OS X operating system, including the AirPort driver, the Help view and the Installer application.

About half of the patches relate to security Relevant Products/Services, such as remote code execution that could permit a hacker to obtain control over a Mac, although there have been no such reported attacks.

Kerberos, iChat

Several of the vulnerabilities are within Kerberos, a network authentication protocol developed at M.I.T. "Running the Kerberos administration daemon may lead to an unexpected application termination or arbitrary code execution with system privileges," Apple said in its Update. Apple credited the M.I.T. Kerberos Team with reporting the issue.

The Libinfo component and LoginWindow software were identified as having flaws that could allow a user to bypass authentication. Video chat was also flagged as being vulnerable. The iChat component had a vulnerability that could allow a malicious user to remotely execute code through a malformed chat request.

Apple also identified a vulnerability in Airport that could allow remote execution in a legacy system, and a patch was included. However, the latest Mac Pro, iMac or MacBook systems are not affected.

The patches also deal with eight identified vulnerabilities in the way the operating system handles disk images. Apple said that mounting a malicious disk image could lead to a security breach.

Largest in March

In early March, Apple also released a large set of fixes. In that batch, the largest so far this year, there were 30 patches for 22 applications. In 2007, the Cupertino, California-based company has issued an average of one security update per month. This is a faster pace than in 2006, when Apple released eight sets of patches in the entire year.

This week's update also addresses several zero-day bugs that were revealed as part of the Month of Apple Bugs in January. The Month of Apple Bugs was a project by two researchers, Kevin Finisterre and the pseudonymous LMH, who reported one flaw per day in Mac OS X or in Mac applications. Each of the vulnerabilities was a previously undocumented security issue.

LMH also led the Month of Kernel Bugs last November. Last summer, researcher HD Moore had orchestrated a Month of Browser Bugs, which focused on unpatched security flaws in Firefox, Internet Explorer, Safari, and Opera.



TOPICS: Business/Economy; Culture/Society; News/Current Events
KEYWORDS: apple; mac; patch
Navigation: use the links below to view more comments.
first previous 1-2021-4041-45 next last
To: Rodney King

That would work nicely as a tagline!


21 posted on 04/20/2007 8:31:40 PM PDT by jdm
[ Post Reply | Private Reply | To 18 | View Replies]

To: rarestia

Would love to but most of my customers are MS users. I spend a majority of my time producing training material (my job), and for the most part they are MS users. Got to go with the dollars.


22 posted on 04/20/2007 8:43:23 PM PDT by doc1019 (Fred Thompson '08)
[ Post Reply | Private Reply | To 20 | View Replies]

To: jdm; Rodney King

It practically is his tagline. He spends a lot of time denying he’s gay, for some reason known best to himself.


23 posted on 04/20/2007 8:45:06 PM PDT by LexBaird (98% satisfaction guaranteed. There's just no pleasing some people.)
[ Post Reply | Private Reply | To 21 | View Replies]

To: TomServo

When i see your FR name, I think of such quotes as “Uncle Jim’s farm of secrets and lies” or “Son, can you identify this bucket of your brother?”


24 posted on 04/20/2007 8:48:17 PM PDT by Army Air Corps (Four fried chickens and a coke)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Army Air Corps

LOL!!! Great stuff! :-)


25 posted on 04/20/2007 9:05:27 PM PDT by TomServo ("Jim Henson's Flying Leatherneck Babies!")
[ Post Reply | Private Reply | To 24 | View Replies]

To: pointsal

I’m running a old powerbook G4 and a new macbook pro.
The “pro” has problems I can’t even bgine to list.
But the G4 is still running 3 years strong.

I’m not impressed with the intel. I’m flat PO’d at Adobe, but that’s a whole different thread.

I’ve never owned a PC so I couldnt’ really compare. But IMO, MAC has lost a lot of quality in the past few years.


26 posted on 04/20/2007 9:10:42 PM PDT by CrappieLuck
[ Post Reply | Private Reply | To 19 | View Replies]

To: 1234; 6SJ7; Abundy; Action-America; af_vet_rr; afnamvet; akatel; Alexander Rubin; Amadeo; ...
Another Security Update thread... PING!

Original Thread from yesterday

If you want on or off the Mac Ping List, Freepmail me.

27 posted on 04/20/2007 9:11:59 PM PDT by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE)
[ Post Reply | Private Reply | To 1 | View Replies]

To: EagleUSA
Think I figured it out — this is 10.4.9. Already had it installed -— :-)

No. It is a security update to 10.4.9... you need to use the "Software Update" under the Blue Apple on the menu bar (top left corner of your screen).

28 posted on 04/20/2007 9:13:38 PM PDT by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE)
[ Post Reply | Private Reply | To 3 | View Replies]

To: rarestia
MAC = flashy GUI with a Linux core.

No Linux here... UNIX...

29 posted on 04/20/2007 9:16:11 PM PDT by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE)
[ Post Reply | Private Reply | To 20 | View Replies]

To: Rodney King
Why would a Mac need a security update? I thought they didn’t get viruses, hacked, etc.

They don't.

Apple likes keeping it that way.

30 posted on 04/20/2007 9:26:06 PM PDT by ReignOfError (`)
[ Post Reply | Private Reply | To 5 | View Replies]

To: TomServo

I have been collecting the boxed sets from Rhino and watching episodes on YouTube (they have about 90% of the episodes on there including the KTMA era).

MST3K rates among my top 10 favourite TV programmes.


31 posted on 04/20/2007 9:32:14 PM PDT by Army Air Corps (Four fried chickens and a coke)
[ Post Reply | Private Reply | To 25 | View Replies]

To: ReignOfError
Hack a Mac contest finds exploitable hole in Safari... successful hacker wins MacBook Pro and $10,000 (Can)... second Mac requires ROOT access to win is still secure.

Note, all of these security patches had been added to the target computers.

32 posted on 04/20/2007 9:37:02 PM PDT by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE)
[ Post Reply | Private Reply | To 30 | View Replies]

To: Rodney King

Don’t underestimate yourself. You’re totally gay.


33 posted on 04/20/2007 9:40:14 PM PDT by Richard Kimball
[ Post Reply | Private Reply | To 18 | View Replies]

To: rarestia
MAC = flashy GUI with a Linux core.

Not Linux. It's BSD. When Leopard comes, it'll become the first BSD certified as a UNIX 2003TM box.

Let me know when Linux finally qualifies as a true UNIX OS.
34 posted on 04/20/2007 10:14:54 PM PDT by George W. Bush
[ Post Reply | Private Reply | To 20 | View Replies]

To: Swordmaker
No. It is a security update to 10.4.9... you need to use the "Software Update" under the Blue Apple on the menu bar (top left corner of your screen).

This is the first security update since we installed 10.4.9, isn't it? I'm assuming that 10.4.9 Combo and this update are all my Tiger needs to be up-to-date.
35 posted on 04/20/2007 10:22:20 PM PDT by George W. Bush
[ Post Reply | Private Reply | To 28 | View Replies]

To: George W. Bush
This is the first security update since we installed 10.4.9, isn't it? I'm assuming that 10.4.9 Combo and this update are all my Tiger needs to be up-to-date.

You assume correctly.

36 posted on 04/20/2007 10:27:00 PM PDT by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE)
[ Post Reply | Private Reply | To 35 | View Replies]

To: jdm
Mentioned Here: #42...

as well.

37 posted on 04/20/2007 10:46:55 PM PDT by Utilizer (What does not kill you... - can sometimes damage you QUITE severely.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker
The trolls really came out for this thread. Too bad there wasn't an original comment among 'em.

#5   - Invulnerability - I thought they didn’t get viruses, hacked, etc.

#10 - the market share canard. - There must have been a "surge" in mac users that make it somewhat worthwhile to hack a mac...

#14 - OSX is perfect canard -  Horror or horrors, the Mac has need of updating and fixes? I thought this was a malady only belonged to MS.

#18 - Mac users are gay - I’d buy a Mac, but I’m not gay. (we think the poster doth protest too much)

#20 - Bogus Mac = Linux comment - MAC = flashy GUI with a Linux core. (Not that there'd be anything wrong with that even if it were true.)

Looks like we have some slackers out there tonight. The gay comment didn't show up until post #18. Y'all can do better than that! Maybe their windows boxes were rebooting, or they were too busy installing one of the recent emergency patches that came out recently for windows.

38 posted on 04/20/2007 10:59:28 PM PDT by zeugma (MS Vista has detected your mouse has moved, Cancel or Allow?)
[ Post Reply | Private Reply | To 27 | View Replies]

To: Swordmaker
Hack a Mac contest finds exploitable hole in Safari... successful hacker wins MacBook Pro and $10,000 (Can)... second Mac requires ROOT access to win is still secure.

By two people on an insecure network, and it required one of them to sit at the machine. And they lowered security to try to achieve that result.

I'm not saying Mac OS is completely bulletproof -- this isn't the first potential exploit in the wild. And of course, no system is secure if the luser is dumb enough to download an app or open an e-mail attachment and then type in a password.

But I have yet to see or hear of OS X spyware, viruses or trojans in the wild. And it's certainly not something any script kiddie can do. The closest thing I've seen is one site where a white-hat used a known exploit to save a text file to my hard drive to warn of a vulnerability back in about 10.2 -- I blocked the applicable port, and Apple patched it soon after.

Note, all of these security patches had been added to the target computers.

I"m nt so sure of that -- the 2007-004 patch was released Thursday, after the contest had begun -- the head of the contest says "all the latest" patches were applied, but it's not clear when he said that or whether he'd heard of the brand-new one. That said, it doesn't really matter, because the 2007-004 documentation doesn't say anything about it patching a Safari vulnerability.

39 posted on 04/21/2007 2:01:31 AM PDT by ReignOfError (`)
[ Post Reply | Private Reply | To 32 | View Replies]

To: Swordmaker

you need to use the “Software Update” under the Blue Apple


Yep, did that some time back and am all UP TO DATE! Thanks.


40 posted on 04/21/2007 7:08:41 AM PDT by EagleUSA
[ Post Reply | Private Reply | To 28 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-45 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson