Win a free GPS from Gadling!

Security Update 2007-005

Apple has just posted its latest security update. This update addresses a boatload of possible vulnerabilities including a number of core unix utilities as well as iChat and VPN. Without further ado, here's a quick rundown of the fixes and the vulnerabilities:

Alias Manager. Impact: Users may be misled into opening a substituted file

BIND. Impact: Multiple vulnerabilities in BIND, the most serious of which is remote denial of service

CoreGraphics. Impact: Opening a maliciously crafted PDF file may lead to an unexpected application termination or arbitrary code execution

crontabs. Impact: The daily /tmp cleanup script may lead to a denial of service

fetchmail. Impact: fetchmail password disclosure may be possible

file. Impact: Running the file command on a maliciously crafted file may lead to an unexpected application termination or arbitrary code execution

iChat. Impact: An attacker on the local network may be able to cause a denial of service or arbitrary code execution

mDNSResponder. Impact: An attacker on the local network may be able to cause a denial of service or arbitrary code execution

PPP. Impact: A local user may obtain system privileges

ruby. Impact: Denial of service vulnerabilities in the Ruby CGI library

screen. Impact: Multiple denial of service vulnerabilities in GNU Screen

texinfo. Impact: A vulnerability in texinfo may allow arbitrary files to be overwritten

VPN. Impact: A local user may obtain system privileges



Thanks Tomasz

Reader Comments (Page 1 of 1)

TUAW Features

iphone app store tuaw tests
Mac 101 ask-tuaw
Mac News
WWDC (251)
.Mac (64)
Accessories (639)
Airport (75)
Analysis / Opinion (1358)
Apple (1659)
Apple Corporate (561)
Apple Financial (190)
Apple History (48)
Apple Professional (54)
Apple TV (162)
Audio (447)
Bad Apple (120)
Beta Beat (152)
Blogging (85)
Bluetooth (17)
Bugs/Recalls (56)
Cult of Mac (873)
Deals (219)
Desktops (115)
Developer (262)
Education (99)
eMac (10)
Enterprise (139)
Features (403)
Freeware (386)
Gaming (376)
Graphic Design (33)
Hardware (1286)
Holidays (37)
Humor (578)
iBook (65)
iLife (235)
iMac (184)
Internet (334)
Internet Tools (1321)
iTS (977)
iTunes (814)
iWork (22)
Leopard (370)
Mac mini (112)
Mac Pro (53)
MacBook (202)
MacBook Air (79)
Macbook Pro (220)
MobileMe (35)
Multimedia (445)
Odds and ends (1450)
Open Source (279)
OS (915)
Peripherals (210)
Podcasting (182)
Podcasts (91)
Portables (197)
PowerBook (135)
PowerMac G5 (50)
Retail (594)
Retro Mac (48)
Rig of the Week (42)
Rumors (633)
Software (4344)
Software Update (417)
Steve Jobs (252)
Stocking Stuffers (50)
Surveys and Polls (97)
Switchers (112)
The Woz (34)
TUAW Business (242)
Universal Binary (281)
UNIX / BSD (61)
Video (905)
Weekend Review (83)
WIN Business (47)
Wireless (85)
Xserve (39)
iPhone/iPod News
iPhone (1620)
iPod Family (2065)
App Store (81)
SDK (19)
Mac Events
One More Thing (27)
Liveblog (1)
Other Events (226)
Macworld (489)
Mac Learning
AppleScript (3)
Ask TUAW (103)
Blogs (85)
Books (26)
Books and Blogs (62)
Cool tools (445)
Hacks (464)
How-tos (486)
Interviews (44)
Mods (187)
Productivity (590)
Reviews (112)
Security (156)
Terminal Tips (59)
Tips and tricks (567)
Troubleshooting (168)
TUAW Features
iPhone 101 (34)
TUAW Labs (3)
Blast From the Past (17)
TUAW Tips (144)
Flickr Find (36)
Found Footage (86)
Mac 101 (94)
TUAW Interview (31)
Widget Watch (198)
The Daily Best (1)
TUAW Faceoff (5)

RESOURCES

RSS NEWSFEEDS

Powered by Blogsmith

Sponsored Links

The Unofficial Apple Weblog (TUAW) bloggers (30 days)

#BloggerPostsCmts
1Cory Bohon844
2Robert Palmer5839
3Steven Sande5423
4Dave Caolo480
5Mat Lu4010
6Erica Sadun333
7Scott McNulty320
8Mike Schramm201
9Brett Terpstra191
10Michael Rose1221
11Giles Turnbull80
12Christina Warren821
13Chris Ullrich30
14Joshua Ellis23
15Kent Pribbernow10
16Jason Clarke10

Featured Galleries

Macworld 2008 Keynote
Macworld 2008 Build-up
Apple Vanity Plates
DiscPainter
Crash Bandicoot Nitro Kart 3D
Macworld Expo 2007 show floor
Apple Texas Hold 'Em
The Macworld Faithful in Line
iPhone First Look

 

    Most Commented On (7 days)

    Recent Comments

    More Apple Analysis

    More from AOL Money and Finance

    Other Weblogs Inc. Network blogs you might be interested in: