Microsoft, Apple Address Security Issues
Microsoft's upcoming Patch Tuesday will address 11 flaws in software like Active Directory and IE, while Apple is fixing 40 vulnerabilities in its latest update.
Microsoft on Thursday said it plans to release 11 security bulletins next week. Separately, Apple released its Security Update 2008-007, addressing 40 vulnerabilities and other stability issues.
Microsoft intends to release its monthly security update on Oct. 14.
More Security Insights
White Papers
- Red Alert: Why Tablet Security Matters - by BlackBerry
- New Visual and Wizard-Driven Paradigms for Exploring Data and Developing Analytic Workflows
Reports
More >>Webcasts
- Outsourcing Security: What Every Potential Cloud Security Customer Should Know
- Maximize ROI with Database Consolidation onto Private Clouds
Four of its bulletins -- affecting Active Directory, Excel Host Integration Server, and Internet Explorer -- are rated "critical."
The Excel vulnerability affects various versions of Microsoft Office, including Microsoft Office for Mac 2004 and 2008.
Six of the Microsoft bulletins are rated "important" and one is rated "moderate." The "important" vulnerabilities have to do with privilege elevation and remote code execution. The "moderate" vulnerability has to do with information disclosure.
The Microsoft bulletins do not appear to address a Windows privilege elevation issue that Microsoft warned about in April and again earlier this week, with the publication of exploit code.
Apple's security update fixes flaws in Apache, Certificates, ClamAV, ColorSync, CUPS, Finder, launchd, libxslt, MySQL Server, Networking, PHP, Postfix, PSNormalizer, QuickLook, rlogin, Script Editor, Single Sign-On, Tomcat, vim, and Weblog.
It is available for Mac OS X 10.4.11 and Mac OS X 10.5.5, either through Apple's Software Update control panel or via download from Apple's site.
Apple's Security Update 2008-007 does not appear to address a reported vulnerability in Apple's iTunes software.
Last month, someone using the name "Securfrog" published proof-of-concept exploit code that supposedly can be used to crash any Web browser with the QuickTime plug-in. The code was tested using iTunes 8.0 and QuickTime 7.5.5.
According to Securfrog, Apple plans to fix this vulnerability in its next release of QuickTime.
Related Reading
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. | |
|
|
T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting! |
Subscribe to RSSResource Links
This Week's Issue
Free Print Subscription
SubscribeCurrent Government Issue
- Going Mobile: As federal agencies embrace devices and apps to meet employee demand, the White House seeks one comprehensive mobile strategy.
- Smartphone Security: The National Security Agency is developing technologies to make commercial devices suitable for intelligence work.
- Read the Current Issue
Technology Whitepapers
- Mobile BI: Actionable Intelligence for the Agile Enterprise
- Creating the Enterprise-Class Tablet Environment - by Yankee Group
- How To Regain IT Control In An Increasingly Mobile World - by BlackBerry
- The BlackBerry PlayBook tablet's Good Bones - by BlackBerry
- Red Alert: Why Tablet Security Matters - by BlackBerry
Featured Resource
This is your portal to all the news, product information, technical data, and other information related to the topic of computer user authentication and certification. Visit us to find out how to ensure that computer users are who they say they are.
Learn More
Featured Reports
Featured Webcasts
- Outsourcing Security: What Every Potential Cloud Security Customer Should Know
- Maximize ROI with Database Consolidation onto Private Clouds
- Effective IT Inventory and Asset Management: From Quagmire to Quick Fix
- Server Virtualization Gets Relief From Tivoli Storage Manager for Virtual Environments
- The ABC's of Cloud Computing in the Midmarket












