Apple worm
A flaw in the OS X CoreGraphics component is the most serious
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Apple issues 13 security fixes

Problems with CoreGraphics, Fetchmail, iChat and mDNSResponder

Shaun Nichols in California, vnunet.com 25 May 2007
ADVERTISEMENT

Apple has issued security fixes for 13 components of its OS X operating system. 

A flaw in the OS X CoreGraphics component is the most serious, as it could allow an attacker to remotely execute code through a specially-crafted PDF file. The vulnerability only affects OS X 10.4.9 and OS X Server 10.4.9.

Apple did not say whether the code execution is confined to the limited privileges of the current user, or whether attackers could execute code at the root level.

Attackers could also target OS X's 'file' for remote code execution. This vulnerability affects all versions of Mac OS X 10.3 and 10.4. No other components suffered from remote execution vulnerabilities.

A flaw in Fetchmail could allow attackers to steal a user's email password. Fetchmail is used to download emails into a user's local machine, and Apple said that the component may not adequately encrypt the password.

Vulnerabilities in Apple's iChat messaging software and mDNSResponder were also patched. Both vulnerabilities could be exploited to remotely execute code, but would require the attacker to be on a local network with the target machine.

Apple also fixed a vulnerability in the way that OS X handles disk images. By convincing a user to mount two identically-named disk images, an attacker could disguise a piece of malicious software as a legitimate application or document.

The security update is available through Apple's software update system component or as a download from the company's website.

See also:

Anne Summers iGasm adLegal eagles circle over Ann Summers stunt  24 May 2007
AppleCompany accused of misleading advertising  22 May 2007
AppleStock market jittery on Apple valuation  21 May 2007
Apple iPhoneFederal Communications Commission approves Apple mobile for use  18 May 2007

All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Skills Summary: Core Java/J2SE (Multi-threading), Java 6, Spring 2, UNIX, Linux, Shell-scripting, Python, Perl, Sybase. A position for a solid Core Java/J2SE Developer at a leading Investment Bank that has done exceptionally with profits in ... more >
| Evolution Recruitment Solutions
German Speaking Technical Support Translators, Poole, Bournemouth are required for my telephony services client. You will need to be IT literate and able to respond to technical queries in German fluently (native speaking ideally). Role ... more >
| Evolution Recruitment Solutions
French Speaking Technical Customer Support officers - Poole, Dorset required for my telephony services client. You will need to be IT literate and able to respond to technical queries in French fluently (native speaking ideally). ... more >
| Evolution Recruitment Solutions
Danish Speaking Technical Customer Support officers - Poole, Dorset required for my telephony services client. You will need to be IT literate and able to respond to technical queries in Danish fluently (native speaking ideally). ... more >
More job opportunities