Skip to Content

Four MOAB bugs swatted by Security Update 2007-002

As Erica just noted, Security Update 2007-02 is out, and four of the open security issues raised by the Month of Apple Bugs project are now history. These problems have been addressed by the ongoing patch efforts of Landon Fuller, but his fixes should defer automatically to the new official versions.
  • Finder -- Mounting a maliciously-crafted disk image may lead to an application crash or arbitrary code execution
  • iChat (2 flaws) -- attackers on the local network may be able to cause iChat to crash, & visiting malicious websites/AIM URLs may lead to an application crash or arbitrary code execution
  • UserNotificationCenter -- local users may be able to escalate to system-wide privileges
Install with caution.

As Erica just noted, Security Update 2007-02 is out, and four of the open security issues raised by the Month of Apple Bugs project are now...
 

Add a Comment

*0 / 3000 Character Maximum

6 Comments

Filter by:
Mo

I wonder if the iChat update fixes rdar:///4833010, which I reported back in November; it's essentially the same as the URL handler vulnerability, although it applies to a different part of iChat's code. Apple haven't marked the bug as anything other than ‘Open’, so I'm guessing not…

February 16 2007 at 8:34 AM Report abuse rate up rate down Reply
mike

davids...

yeah, funny, I never noticed any of those 'bugs'...

*shrugs

February 16 2007 at 2:08 AM Report abuse rate up rate down Reply
Justin

The update seems to work fine for me.

February 15 2007 at 7:14 PM Report abuse rate up rate down Reply
Mark Fleser

There's also a daylight savings time update and a java updated.

February 15 2007 at 7:05 PM Report abuse rate up rate down Reply
Justin

I'm going to try this update out. If it doesn't work I can just reboot from my Sandbox to my main system partition.

February 15 2007 at 7:02 PM Report abuse rate up rate down Reply
davids

I'm glad to see that months are now only 5-6 days long.

February 15 2007 at 6:58 PM Report abuse rate up rate down Reply
Buy an ad here

Hot Apps on TUAW

Tweets

© 2012 AOL Inc. All Rights Reserved.