iPhoto and ProKit updates hitting today

In the hustle and bustle of product introductions today, another couple of software updates slipped out the door. The 16 MB iPhoto 7.1.2 update promises the "overall stability" we all crave, while the ProKit update (no link on Apple's site yet) "improves reliability for Apple's professional applications and is recommended for all users of Final Cut Studio, Final Cut Express, Aperture, Logic Studio and Logic Express."
Meanwhile, in a separate security bulletin (link as in the image), Apple acknowledged an iPhoto vulnerability that would allow a maliciously-crafted photocast to hijack your machine, if you were to subscribe to it; said vulnerability is now fixed in 7.1.2. Yikes. Full details after the jump.
Your mileage, as always, may vary.
Thanks Erik!
iPhoto 7.1.2 security info (from Apple):
CVE-ID: CVE-2008-0043
Available for: iPhoto '08 7.1
Impact: Subscribing to a maliciously-crafted photocast may lead to
arbitrary code execution
Description: A format string vulnerability exists in iPhoto. By
enticing a user to subscribe to a maliciously-crafted photocast, a
remote attacker may cause arbitrary code execution. This update
addresses the issue through improved handling of format strings when
processing photocast subscriptions. Credit to Nathan McFeters of
Ernst & Young's Advanced Security Center for reporting this issue.
iPhoto 7.1.2 may be obtained from the Software Update pane in
System Preferences, or Apple's Software Downloads web site:
http://www.apple.com/support/downloads/
The download file is named: "iPhoto_712.dmg"
Its SHA-1 digest is: d7ea54d2ecc4362b97aec563ffa2cb2d3e700bda
Information will also be posted to the Apple Product Security
web site:
http://docs.info.apple.com/article.html?artnum=61798
Share
Source: http://apple.com/support
Categories
In the hustle and bustle of product introductions today, another couple of software updates slipped out the door. The 16 MB iPhoto 7.1.2...
Add a Comment
No fix for the overload errors in Logic. A shame.
February 06 2008 at 10:27 AM Report abuse Permalink rate up rate down ReplyWhy, oh why won't apple store tags and comments in a jpgs iptc? I know you can import/export them, but this should be a default.
Oh well, just going to have to wait for the Mac version of Picasa coming later this year.
Still no 2008 in Aperture source list.
February 06 2008 at 6:27 AM Report abuse Permalink rate up rate down ReplySweet merciful crap! FCP stopped crashing in Leopard from certain plugins :D:D:D:D:D:D:D
February 05 2008 at 11:25 PM Report abuse Permalink rate up rate down ReplyFYI- 10.5.2 was issued privately to developers last Thursday.
February 05 2008 at 7:23 PM Report abuse Permalink rate up rate down ReplyFine, I'll never be snarky again. :(
February 06 2008 at 2:10 AM Report abuse Permalink rate up rate down ReplyHm, started Software Update - it hung with the spinning beach ball. Had to force quit it, no program would start after that and a reboot also hung (had to turn my iMac off by pressing the power button).
After a long boot up Spotlight is reindexing. I don't know what happened but it sure spooked me. I'm not touching those again until more people have. * shudders *
Hot Apps on TUAW
Deals of the Day
more deals- Refurb Apple MacBook Air Laptops: 12" 64GB SSD for $699 + free shipping
- JVC Motion Sensing Clock Radio with Dual iPod Docks for $55 + free shipping
- Apple iPhone Headset with Mic for $4 + $2 s&h
- miFrame Picture Frame Dock for iPad for $64 + $8 s&h
- Refurb Apple iPod nano 8GB MP3 Player for $99 + free shipping, 16GB for $119
- Hannspree Apple-Shaped 28" 1080p LCD HDTV for $270 + free shipping
Software Updates
more updates- EFI Firmware Update brings Lion Internet Recovery to 2010-model Macs
- OS X Lion 10.7.3 released with Safari 5.1.3, Wi-Fi bug fix
- Aperture updated to 3.2.2, addresses Photo Stream issue
- Apple updates Keynote to address Lion issues
- Google Search app gets new look on iPad
- Apple releases Apple TV Software Update 4.4.3



10 Comments