eWeek Security Watch
Advertisement
Advertisement
February 6, 2008 1:46 PM

Hey Apple, Where's my iPhoto Security Patch?



Two days ago, Apple released iPhoto 7.1.2 to patch a format string vulnerability that was found and reported by Ernst & Young researcher Nate McFeters.

The language in the advisory from Apple sounds pretty scary:

A format string vulnerability exists in iPhoto. By enticing a user to subscribe to a maliciously crafted photocast, a remote attacker may cause arbitrary code execution. This update addresses the issue through improved handling of format strings when processing photocast subscriptions.

Whenever I see remote and code execution in the same sentence, I get nervous.

[ALSO SEE: QuickTime Under Seige: Another Zero Day Exploit Released]

I've been hitting Software Update repeatedly on my MacBook for the last 36 hours and here's what Apple tells me:

Hey Apple, Where's my iPhoto Patch?

I'm running iPhoto 6.0.6 (322) on this machine so this is definitely an out-of-date version of the software. What gives?

While I'm at it, what's the status of the one-month-old QuickTime RTSP flaw that also brings code execution risk?

UPDATE: Turns out this update is only available for iPhoto '08 7.1 (iLife '08). I'm running iLife '06 (6.0.x), and therefore, a fix isn't available for me.

Problem is, I don't know for sure (does Apple?) that iLife '06 isn't affected.

ANOTHER UPDATE: Via Twitter, Rich Mogull has a better explanation:

It's a web gallery vuln, which isn't a feature in iPhoto 6.

Phew. I'm now thinking Apple's bulletins desperately need a "not affected" section.

Also see: Technical details on the bug from Nate McFeters.

TrackBack

TrackBack

http://securitywatch.eweek.com/cgi-bin/mte/mt-tb.cgi/12654

Comments (1)

AdamC :

Sad to see this kind of stuff from a writer who is too stupid to check with Macupdate.com to download the update..

Post a Comment

 
 


RSS Syndication
Advertisement
Advertisement
Security Watch     Contact Us | Advertise | Site Map
Ziff Davis Enterprise

Ziff Davis Enterprise Home | Contact Us | Advertise | Link to Us | Reprints | Magazine Subscriptions | Newsletters
RSS Feeds | White Papers | ROI Calculators | Tech Podcasts | Tech Video |

Baseline | Careers | Channel Insider | CIO Insight | DesktopLinux | DeviceForge | DevSource | eSeminars |
eWEEK | LinuxDevices | Linux Watch | Microsoft Watch | Mid-market | Networking | PDF Zone |
Publish | eWeek Security | Strategic Partner | Web Buyer's Guide | Windows for Devices

Developer Shed | Dev Shed | ASP Free | Dev Articles | Dev Hardware | SEO Chat | Tutorialized | Scripts |
Code Walkers | Web Hosters | Dev Mechanic | Dev Archives | IT Marketplace | igrep

Use of this site is governed by our Terms of Use and Privacy Policy

Copyright ©1996-2007 Ziff Davis Enterprise, Inc. All Rights Reserved. Security Watch is a trademark of Ziff Davis Enterprise, Inc. Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise Inc. is prohibited.

Ziff Davis Enterprise