Newsletter:

Skip Navigation LinksHome > News > Security > Latest Apple update fixes 25 flaws

Latest Apple update fixes 25 flaws

By Shaun Nichols
23 April 2007 12:30PM
Tags: latest | apple | update | fixes | 25 | flaws

Vulnerabilities in AirPort and Kerberos, among others.

Apple has released its fifth security update of the year, covering 25 vulnerabilities in 20 Mac OS X components. 

Fifteen of the vulnerabilities could allow an attacker to execute malicious code, but no working exploits have been reported for any of the attacks so far.

Three of the remote code execution vulnerabilities lie within Kerberos, a network security component developed by MIT. Apple credits the MIT Media Lab with reporting all three vulnerabilities. 

Other fixes were for the Libinfo component and the LoginWindow software, which contained two flaws allowing users to bypass the authentication screen.

Apple's iChat video chat component received a fix for a vulnerability that could allow an attacker to remotely execute code on a user's system through a malformed video chat request.

The update also addresses a vulnerability in AirPort which could allow remote execution in several legacy systems. None of Apple's latest Mac Pro, iMac or MacBook systems is affected by the flaw.

The vulnerability is also unrelated to the pair of flaws patched earlier this month in the 802.11n AirPort systems.  

The update is the second largest Apple has issued this year. The company released a security update last month containing 30 patches in 22 applications. 

Copyright © 2008 vnunet.com

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 


Tripwire - Click here to win an iTouch





Product Reviews

Star Rating
The AdventNet Manage-Engine Password Manager Pro provides a complete system for password management in one...
Star Rating
The Cyber-Ark Enterprise Password Vault, or EPV, is a high-end password management powerhouse.
Star Rating
The Hitachi ID-Archive sets its focus on password randomisation.
Star Rating
The Lieberman Software Enterprise Random Pass­word Manager is a full-on password manager and randomiser for...
Star Rating
Proginet SecurForce is a little bit of a horse of a different color for this month's Group Test.
Unified Communications Podcast Centre

TopTopics
(4866) -  broadband
(4761) -  telstra
(4724) -  nbn
(4330) -  internet
(4004) -  iinet
(3977) -  copyright
(3977) -  afact
(3675) -  servers
(3675) -  mipi
(2850) -  internode
(2431) -  network
(2193) -  microsoft
(1562) -  data
(1518) -  software
(1367) -  centre