Commentary

George Hulme
 

Apple Fixes Security Holes, Updates Leopard

Where last week finished up with having to patch my Firefox browser with two handfuls of security patches, Apple has released its first batch of security updates for this year. And it's a biggie.

Where last week finished up with having to patch my Firefox browser with two handfuls of security patches, Apple has released its first batch of security updates for this year. And it's a biggie.I no more sat down at my system after dinner, and I'm greeted with a 180 MB update through the OS X Software Update feature. It's both an update to Leopard 10.5.2 and more than 10 security fixes.

The majority of the fixes apply to Leopard and Leopard Server.


More Security Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

The fixes include one aimed at the OS's Foundation and prevents a malicious Web URL from allowing renegade code to be launched, or crashing applications. Others include mending a gaffe in Parental Controls, Launch Services, NFS client and server vulnerabilities, as well as issues with X11 X Font Server.

While it's tough to tell which vulnerabilities are the most critical, because Apple doesn't rank its vulnerabilities as clearly as Microsoft, one of the worst vulnerabilities patched appears to be in its Mail client.

According to Apple's advisory, users who click on an especially crafted URL will be hit with code of the attacker's choice: "Affected users accessing a URL in a message may experience an arbitrary code execution. Apple says, "An implementation issue exists in Mail's handling of file:// URLs, which may allow arbitrary applications to be launched without warning when a user clicks a URL in a message. This issue does not affect systems running Mac OS X v10.5 or later."

And all of this fun on the eve of Microsoft's patch Tuesday. I'd better plan on spending some extra time in boot camp tomorrow.

More information from Apple on this evening's update is available here.


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links