Apple OS X 10.6.5 Patches 131 Security Flaws

About 40% of the fixes involve Adobe Flash, lending some credence to Apple's criticism of the plug-in.

Slideshow: 10 Killer Mac Applications
Slideshow: 10 Killer Mac Applications
(click image for larger view and for full slideshow)

On Wednesday, Apple released OS X 10.6.5 and Security Update 2010-007, patching 131 vulnerabilities across both Mac OS X and Mac OS X Server.


More Security Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

"Many of the vulnerabilities could be exploited by malicious hackers to run unauthorized code on your Mac computer, opening you up to the potential of being spied upon, having information stolen, or cybercriminals commandeering your Mac into becoming part of a botnet," said Graham Cluley, senior technology consultant at Sophos.

When it comes to updating, "don't delay," he said.

Full details of the vulnerabilities addressed are covered in Apple's related knowledgebase article, released Thursday.

Interestingly, among the updates is a patch for the Flash Player plug-in. According to Apple, "multiple issues exist in the Adobe Flash Player plug-in, the most serious of which may lead to arbitrary code execution. The issues are addressed by updating the Flash Player plug-in to version 10.1.102.64."

In fact, according to AppleInsider, while 42% of the 131 vulnerabilities patched by 10.6.5 address Apple's own code, an equal number relate to Adobe Flash. That revelation adds some perspective to Apple's public denigration of Flash.

What's curious, however, is what Apple hasn't patched. Notably, OS X 10.5 remains vulnerable to a variation of the publicly disclosed FreeType JailbreakMe iPhone exploit.

According to Core Security, a penetration testing firm, "this vulnerability could be used by a remote attacker to execute arbitrary code, by enticing the user of Mac OS X v10.5.x to view or download a PDF document containing an embedded malicious CFF font."

Core Security said that it first alerted Apple to the vulnerability in August. "According to information provided to us by Apple, a patch for this fix has already been developed," said Core Security. "Apple provided us a release date for this patch in two opportunities but then failed to meet [their] deadlines without giving us any notice or explanation."

With the vulnerability still not patched, Core Security recommends that any OS X 10.5 users immediately upgrade to OS X 10.6. One problem, however, is that after OS X 10.5, Apple dropped support for Macs based on the PowerPC chipset. Accordingly, owners of older Macs will remain vulnerable to the attack until Apple releases an OS X 10.5 patch.

As perimeters melt away, security goes beyond encryption, authentication, and monitoring. We also need to ensure privileged users aren't betraying trust. In this report, we'll cover ways to track who did what to which system, and when. Download the report here (registration required).

Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS

Resource Links