eWeek Security Watch
Advertisement
Advertisement
April 20, 2007 1:05 AM

Apple Stitches Up 25 Holes in Mac OS X



Apple released 25 security patches for Mac OS X on Thursday, the most serious of which could allow a remote attacker to crash a system or execute arbitrary code.

The patches address holes found throughout the Mac operating system, from the VideoConference framework to placement of the Login window. Some of the patches address holes found in third-party products working with Macs, including three glitches found in Macs working in conjunction with Kerberos, MIT's network authentication protocol. Many of the glitches allow local users to escalate privileges.

Apple, which touts the supposed superiority of its Macintosh operating system over Microsoft's Windows, has been putting out a healthy load of security patches all year.

In March, Apple patched a heap corruption vulnerability in QuickTime. Later that month, the company issued a security update to plug dozens of holes in both the client and server versions of Mac OS X 10.4.9.

Before that, in February, Apple patched "highly critical" OS X and iChat vulnerabilities.

This all came on top of a grim start of the year for Apple: The Month of Apple Bugs launched on Jan. 1, less than 24 hours after the release of working exploits for two critical media player flaws—QuickTime and VLC. Later that month, Apple shipped an Airport security update to fix a kernel panic issue that could allow attackers to cause system crashes.

This latest shipment of 25 security updates came on the same day that a "pwn-2-own" contest launched at the CanSecWest security conference here in Vancouver. Hackers clustered in hotel rooms were feverishly trying to exploit the two unpatched Macs downstairs in the main conference hall, but Apple hopped on the phone to inform the conference organizers of the security update release. The show's organizers patched the Macs before they were hacked.

The patches can be downloaded and installed from Apple's Software Update or its Apple Downloads site.

Create, Communicate, Collaborate with IT Professionals at Ziff Davis Enterprise IT Link

TrackBack

TrackBack

http://securitywatch.eweek.com/cgi-bin/mte/mt-tb.cgi/10806

Post a Comment

 
 


RSS Syndication
Advertisement
Advertisement
Security Watch     Contact Us | Advertise | Site Map
Ziff Davis Enterprise

Ziff Davis Enterprise Home | Contact Us | Advertise | Link to Us | Reprints | Magazine Subscriptions | Newsletters
RSS Feeds | White Papers | ROI Calculators | Tech Podcasts | Tech Video |

Baseline | Careers | Channel Insider | CIO Insight | DesktopLinux | DeviceForge | DevSource | eSeminars |
eWEEK | LinuxDevices | Linux Watch | Microsoft Watch | Mid-market | Networking | PDF Zone |
Publish | eWeek Security | Strategic Partner | Web Buyer's Guide | Windows for Devices

Developer Shed | Dev Shed | ASP Free | Dev Articles | Dev Hardware | SEO Chat | Tutorialized | Scripts |
Code Walkers | Web Hosters | Dev Mechanic | Dev Archives | IT Marketplace | igrep

Use of this site is governed by our Terms of Use and Privacy Policy

Copyright ©1996-2007 Ziff Davis Enterprise, Inc. All Rights Reserved. Security Watch is a trademark of Ziff Davis Enterprise, Inc. Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise Inc. is prohibited.

Ziff Davis Enterprise