Newsletter:

Skip Navigation LinksHome > News > Security > Apple plugs five security holes

Apple plugs five security holes

By Tom Sanders
30 June 2006 09:58AM
Tags: apple | plugs | five | security | holes

Apple has released a security update for its OS X operating system that plugs five vulnerabilities.

Apple has released a security update for its OS X operating system that plugs five vulnerabilities.

Apple does not issue severity ratings for vulnerabilities in its software, but at least two of the repaired vulnerabilities could allow an attacker to take control of a system.

The update to version 10.4.7 repairs a vulnerability in the way that OS X handles TIFF images which could be exploited through a specially crafted image. The vulnerability can cause an application to crash or allow for arbitrary code execution.

The ClamAV application that is bundled with the server version of the operating system could also allow an attacker to take over control of a system, Apple warned.

The attacker would have to set up a spoofed database mirror for the ClamAV antivirus application.

Of the remaining plugged holes, a vulnerability in the AFP server is vulnerable to a privilege escalation that can lead to disclosure of sensitive information.

The Launchd program is suffering from a vulnerability that could allow a local user to gain additional privileges and the Open Directory Server and is susceptible to a security flaw that gives attackers an opportunity to crash the application.

Users can update their system through the update service built into OS X or by manually downloading the patch from the Apple support website.

Copyright © 2008 vnunet.com

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 


Tripwire - Click here to win an iTouch



Product Reviews

Star Rating
The Lieberman Software Enterprise Random Pass­word Manager is a full-on password manager and randomiser for...
Star Rating
Proginet SecurForce is a little bit of a horse of a different color for this month's Group Test.
Star Rating
On the surface, RoboForm Enterprise starts out looking like a single sign-on product, but that is just on the...
Star Rating
The Symark PowerBroker is a policy-driven, privileged access control application.
Star Rating
The Symark PowerKeeper is a hardened appliance. It comes with a sealed operating system that provides a...
iTnews 2009 Job Survey

TopTopics
(7278) -  top
(3142) -  microsoft
(2312) -  broadband
(2210) -  content
(2150) -  company
(2118) -  data
(1927) -  terria
(1863) -  isp
(1811) -  nbn
(1720) -  telstra
(1712) -  filtering
(1581) -  internode
(1538) -  voip
(1439) -  centre
(1148) -  consumers