Month Of Patches Takes On Month Of Apple Bugs - InformationWeek
IoT
IoT
Software // Enterprise Applications
News
1/3/2007
12:53 PM
50%
50%
RELATED EVENTS
Moving UEBA Beyond the Ground Floor
Sep 20, 2017
This webinar will provide the details you need about UEBA so you can make the decisions on how bes ...Read More>>

Month Of Patches Takes On Month Of Apple Bugs

A former Apple Computer developer posted patches for the first two vulnerabilities disclosed by the bug-a-day hacker crusade, and promised to meet each new flaw with a fix.

A day after the "Month of Apple Bugs" campaign debuted, a former Apple Computer developer posted patches for the first two vulnerabilities disclosed by the bug-a-day hacker crusade, and promised to meet each new flaw with a fix.

Landon Fuller, now involved in the DarwinPorts project -- an effort to install open-source software on the Mac OS X, Darwin, and OpenDarwin operating systems -- stepped in with the fixes as "part brain exercise, part public service," he wrote on his blog.

"You can download the source [code], or download a pre-built binary," Fuller said of the patch for the first Month of Apple Bugs (MoAB) vulnerability, which involves Apple's QuickTime media player. "You'll also need to install Application Enhancer to use this." Application Enhancer is a free-of-charge download from Unsanity, a St. George, Utah-based Mac developer.

The second MoAB flaw, which impacts the VLC media player, has also been patched by Fuller; the VLC developers have issued their own update to the media player. Fuller's second fix also requires Application Enhancer to install.

"If you'd like to help with tomorrow's MoAB vulnerability please feel free to send me patches or other information," Fuller added.

MoAB is a follow-up to November's "Month of Kernel Bugs" campaign, and is co-hosted by that project's poster, a hacker who goes by the initials "LMH," and his partner, Kevin Finisterre, a researcher who has also uncovered numerous Mac vulnerabilities.

Apple has been mum about MoAB. Tuesday, company spokesman Anuj Nayar simply said that "Apple takes security very seriously and has a great track record of addressing potential vulnerabilities before they can affect users."

The MoAB site can be found here; the day's vulnerability is typically posted during the afternoon, Pacific time.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
[Interop ITX 2017] State Of DevOps Report
[Interop ITX 2017] State Of DevOps Report
The DevOps movement brings application development and infrastructure operations together to increase efficiency and deploy applications more quickly. But embracing DevOps means making significant cultural, organizational, and technological changes. This research report will examine how and why IT organizations are adopting DevOps methodologies, the effects on their staff and processes, and the tools they are utilizing for the best results.
Register for InformationWeek Newsletters
White Papers
Current Issue
IT Strategies to Conquer the Cloud
Chances are your organization is adopting cloud computing in one way or another -- or in multiple ways. Understanding the skills you need and how cloud affects IT operations and networking will help you adapt.
Video
Slideshows
Twitter Feed
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Flash Poll