Skip to Content

iPhoto and ProKit updates hitting today


In the hustle and bustle of product introductions today, another couple of software updates slipped out the door. The 16 MB iPhoto 7.1.2 update promises the "overall stability" we all crave, while the ProKit update (no link on Apple's site yet) "improves reliability for Apple's professional applications and is recommended for all users of Final Cut Studio, Final Cut Express, Aperture, Logic Studio and Logic Express."

Meanwhile, in a separate security bulletin (link as in the image), Apple acknowledged an iPhoto vulnerability that would allow a maliciously-crafted photocast to hijack your machine, if you were to subscribe to it; said vulnerability is now fixed in 7.1.2. Yikes. Full details after the jump.

Your mileage, as always, may vary.

Thanks Erik!
iPhoto 7.1.2 security info (from Apple):

CVE-ID: CVE-2008-0043
Available for: iPhoto '08 7.1
Impact: Subscribing to a maliciously-crafted photocast may lead to
arbitrary code execution
Description: A format string vulnerability exists in iPhoto. By
enticing a user to subscribe to a maliciously-crafted photocast, a
remote attacker may cause arbitrary code execution. This update
addresses the issue through improved handling of format strings when
processing photocast subscriptions. Credit to Nathan McFeters of
Ernst & Young's Advanced Security Center for reporting this issue.

iPhoto 7.1.2 may be obtained from the Software Update pane in
System Preferences, or Apple's Software Downloads web site:
http://www.apple.com/support/downloads/

The download file is named: "iPhoto_712.dmg"
Its SHA-1 digest is: d7ea54d2ecc4362b97aec563ffa2cb2d3e700bda

Information will also be posted to the Apple Product Security
web site:
http://docs.info.apple.com/article.html?artnum=61798

Categories

Software Update

In the hustle and bustle of product introductions today, another couple of software updates slipped out the door. The 16 MB iPhoto 7.1.2...
 

Add a Comment

*0 / 3000 Character Maximum

10 Comments

Filter by:
Rollins

No fix for the overload errors in Logic. A shame.

February 06 2008 at 10:27 AM Report abuse rate up rate down Reply
edwardsnh

Why, oh why won't apple store tags and comments in a jpgs iptc? I know you can import/export them, but this should be a default.

Oh well, just going to have to wait for the Mac version of Picasa coming later this year.

February 06 2008 at 10:10 AM Report abuse rate up rate down Reply
Niklas

Still no 2008 in Aperture source list.

February 06 2008 at 6:27 AM Report abuse rate up rate down Reply
Evan Adnams

Sweet merciful crap! FCP stopped crashing in Leopard from certain plugins :D:D:D:D:D:D:D

February 05 2008 at 11:25 PM Report abuse rate up rate down Reply
Bill Mac

FYI- 10.5.2 was issued privately to developers last Thursday.

February 05 2008 at 7:23 PM Report abuse rate up rate down Reply
1 reply to Bill Mac's comment
Macroy

Fine, I'll never be snarky again. :(

February 06 2008 at 2:10 AM Report abuse rate up rate down Reply
Lars

Hm, started Software Update - it hung with the spinning beach ball. Had to force quit it, no program would start after that and a reboot also hung (had to turn my iMac off by pressing the power button).

After a long boot up Spotlight is reindexing. I don't know what happened but it sure spooked me. I'm not touching those again until more people have. * shudders *

February 05 2008 at 5:31 PM Report abuse rate up rate down Reply
3 replies to Lars's comment
Buy an ad here

Hot Apps on TUAW

Tweets

© 2012 AOL Inc. All Rights Reserved.