Apple patches DNS hole

By

Apple has released a security patch which fixes a much-publicised flaw in Domain Name Server (DNS) security, which could have allowed cache-poisoning attacks.

Apple patches DNS hole
Security Update 2008-005, which is available through Software Update under the Apple icon in the menu bar also fixes a number of other security issues as follows.

Open Scripting Architecture Fixes an elevated privileges bug when loading plugins CarbonCore Fixes stack overflow in handling long file names. Potential code execution.

CoreGraphics Fixes two bugs, both code execution, one for malicious graphics the other for malicious PDFs. Data Detectors Engine Prevents engine crashes when parsing maliciously-crafted content. Disk Utility Stops local users from obtaining System privileges.

OpenLDAP Fixes an ASN parsing bug which can lead to a crash. OpenSSL Repairs range checking error which can lead to remote code execution. PHP Fixes five different bugs, one of which can lead to remote code execution.

QuickLook Blocks maliciously-crafted Microsoft Office files which can cause QuickLooks to crash or allow remote code execution. rsync Fixes path validation errors.

The 65Mb, download which is available as you read, addresses all of the above problems, some of which were first reported way back in September 2007. ยต
Got a news tip for our journalists? Share it with us anonymously here.
theinquirer.net (c) 2010 Incisive Media
Tags:

Most Read Articles

Phishing attack nets enormous npm supply chain compromise

Phishing attack nets enormous npm supply chain compromise

Service NSW centralises security, networking in mammoth CloudOps overhaul

Service NSW centralises security, networking in mammoth CloudOps overhaul

VicRoads to phase out passwords in favour of passkeys

VicRoads to phase out passwords in favour of passkeys

Apple adds "mercenary spyware" protection to new A19 chip

Apple adds "mercenary spyware" protection to new A19 chip

Log In

  |  Forgot your password?