Filed under: Software Update, Security
Apple releases Security Update 2008-007

- Client systems running Leopard
- Server systems running Leopard
- Client systems running Mac OS X 10.4.11 (Intel)
- Client systems running Mac OS X 10.4.11 (PPC)
- Server systems running Mac OS X 10.4.11 (PPC)
- Server systems running Mac OS X 10.4.11 (Universal)
Continue reading for a change log for this update.
Security Update 2008-007
-
Apache
CVE-ID: CVE-2007-6420, CVE-2008-1678, CVE-2008-2364
Available for: Mac OS X v10.5.5, Mac OS X Server v10.5.5
Impact: Multiple vulnerabilities in Apache 2.2.8
Description: Apache is updated to version 2.2.9 to address several vulnerabilities, the most serious of which may lead to cross site request forgery. Apache version 2 is not bundled with Mac OS X Client systems prior to version 10.5. Apache version 2 is bundled with Mac OS X Server v10.4.x systems, but is not active by default. Further information is available via the Apache web site at http://httpd.apache.org/
-
Certificates
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.5, Mac OS X Server v10.5.5
Impact: Root certificates have been updated
Description: Several trusted certificates were added to the list of system roots. Several existing certificates were updated to their most recent version. The complete list of recognized system roots may be viewed via the Keychain Access application.
-
ClamAV
CVE-ID: CVE-2008-1389, CVE-2008-3912, CVE-2008-3913, CVE-2008-3914
Available for: Mac OS X Server v10.4.11, Mac OS X Server v10.5.5
Impact: Multiple vulnerabilities in ClamAV 0.93.3
Description: Multiple vulnerabilities exist in ClamAV 0.93.3, the most serious of which may lead to arbitrary code execution. This update addresses the issues by updating to ClamAV 0.94. ClamAV is not bundled on Mac OS X Client systems. Further information is available via the ClamAV website at http://www.clamav.net/
-
ColorSync
CVE-ID: CVE-2008-3642
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.5, Mac OS X Server v10.5.5
Impact: Viewing a maliciously crafted image may lead to an unexpected application termination or arbitrary code execution
Description: A buffer overflow exists in the handling of images with an embedded ICC profile. Opening a maliciously crafted image with an embedded ICC profile may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation of ICC profiles in images. Credit: Apple.
-
CUPS
CVE-ID: CVE-2008-3641
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.5, Mac OS X Server v10.5.5
Impact: A remote attacker may be able to cause arbitrary code execution with the privileges of the 'lp' user
Description: A range checking issue exists in the Hewlett-Packard Graphics Language (HPGL) filter, which may cause arbitrary memory to be overwritten with controlled data. If Printer Sharing is enabled, a remote attacker may be able to cause arbitrary code execution with the privileges of the 'lp' user. If Printer Sharing is not enabled, a local user may be able to obtain elevated privileges. This update addresses the issue by performing additional bounds checking. Credit to regenrecht working with TippingPoint's Zero Day Initiative for reporting this issue.
-
Finder
CVE-ID: CVE-2008-3643
Available for: Mac OS X v10.5.5, Mac OS X Server v10.5.5
Impact: A file on the Desktop may lead to a denial of service
Description: An error recovery issue exists in Finder. A maliciously crafted file on the Desktop which causes Finder to unexpectedly terminate when generating its icon will cause Finder to continually terminate and restart. Until the file is removed, the user account is not accessible via Finder's user interface. This update addresses the issue by generating icons in a separate process. This issue does not affect systems prior to Mac OS X v10.5. Credit to Sergio 'shadown' Alvarez of n.runs AG for reporting this issue.
-
launchd
Available for: Mac OS X v10.5.5, Mac OS X Server v10.5.5
Impact: Applications may fail to enter a sandbox when requested
Description: This update addresses an issue introduced in Mac OS X v10.5.5. An implementation issue in launchd may cause an application's request to enter a sandbox to fail. This issue does not affect programs that use the documented sandbox_init API. This update addresses the issue by providing an updated version of launchd. This issue does not affect systems prior to Mac OS X v10.5.5.
-
libxslt
CVE-ID: CVE-2008-1767
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.5, Mac OS X Server v10.5.5
Impact: Processing an XML document may lead to an unexpected application termination or arbitrary code execution
Description: A heap buffer overflow issue exists in the libxslt library. Viewing a maliciously crafted HTML page may lead to an unexpected application termination or arbitrary code execution. Further information on the patch applied is available via http://xmlsoft.org/XSLT/ Credit to Anthony de Almeida Lopes of Outpost24 AB, and Chris Evans of Google Security Team for reporting this issue.
-
MySQL Server
CVE-ID: CVE-2007-2691, CVE-2007-5969, CVE-2008-0226, CVE-2008-0227, CVE-2008-2079
Available for: Mac OS X Server v10.5.5
Impact: Multiple vulnerabilities in MySQL 5.0.45
Description: MySQL is updated to version 5.0.67 to address several vulnerabilities, the most serious of which may lead to arbitrary code execution. These issues only affect Mac OS X Server systems. Further information is available via the MySQL web site at http://dev.mysql.com/doc/refman/5.0/en/releasenotes-cs-5-0-67.html
-
Networking
CVE-ID: CVE-2008-3645
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.5, Mac OS X Server v10.5.5
Impact: A local user may obtain system privileges
Description: A heap buffer overflow exists in the local IPC component of configd's EAPOLController plugin, which may allow a local user to obtain system privileges. This update addresses the issue through improved bounds checking. Credit: Apple.
-
PHP
CVE-ID: CVE-2007-4850, CVE-2008-0674, CVE-2008-2371
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X Server v10.5.5
Impact: Multiple vulnerabilities in PHP 4.4.8
Description: PHP is updated to version 4.4.9 to address multiple vulnerabilities, the most serious of which may lead to arbitrary code execution. Further information is available via the PHP website at http://www.php.net/ These issues only affect systems running Mac OS X v10.4.x, Mac OS X Server v10.4.x, or Mac OS X Server v10.5.x.
-
Postfix
CVE-ID: CVE-2008-3646
Available for: Mac OS X v10.5.5
Impact: A remote attacker may be able to send mail directly to local users
Description: An issue exists in the Postfix configuration files. For a period of one minute after a local command-line tool sends mail, postfix is accessible from the network. During this time, a remote entity who could connect to the SMTP port may send mail to local users and otherwise use the SMTP protocol. This issue does not cause the system to be an open mail relay. This issue is addressed by modifying the Postfix configuration to prevent SMTP connections from remote machines. This issue does not affect systems prior to Mac OS X v10.5 and does not affect Mac OS X Server. Credit to Pelle Johansson for reporting this issue.
-
PSNormalizer
CVE-ID: CVE-2008-3647
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.5, Mac OS X Server v10.5.5
Impact: Viewing a maliciously crafted PostScript file may lead to an unexpected application termination or arbitrary code execution
Description: A buffer overflow exists in PSNormalizer's handling of the bounding box comment in PostScript files. Viewing a maliciously crafted PostScript file may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation of PostScript files. Credit: Apple.
-
QuickLook
CVE-ID: CVE-2008-4211
Available for: Mac OS X v10.5.5, Mac OS X Server v10.5.5
Impact: Downloading or viewing a maliciously crafted Microsoft Excel file may lead to an unexpected application termination or arbitrary code execution
Description: A signedness issue exists in QuickLook's handling of columns in Microsoft Excel files may result in an out-of-bounds memory access. Downloading or viewing a maliciously crafted Microsoft Excel file may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation of Microsoft Excel files. This issue does not affect systems prior to Mac OS X v10.5. Credit: Apple.
-
rlogin
CVE-ID: CVE-2008-4212
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.5, Mac OS X Server v10.5.5
Impact: Systems that have been manually configured to use rlogin and host.equiv may unexpectedly permit root login
Description: The manpage for the configuration file hosts.equiv indicates that entries do not apply to root. However, an implementation issue in rlogind causes these entries to also apply to root. This update addresses the issue by properly disallowing rlogin from the root user if the remote system is in hosts.equiv. The rlogin service is not enabled by default in Mac OS X, and must be manually configured in order to be enabled. Credit to Ralf Meyer for reporting this issue.
-
Script Editor
CVE-ID: CVE-2008-4214
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.5, Mac OS X Server v10.5.5
Impact: A local user may gain the privileges of another user that is using Script Editor
Description: An insecure file operation issue exists in the Script Editor application when opening application scripting dictionaries. A local user can cause the scripting dictionary to be written to an arbitrary path accessible by the user that is running the application. This update addresses the issue by creating the temporary file in a secure location. Credit: Apple.
-
Single Sign-On
Available for: Mac OS X v10.5.5, Mac OS X Server v10.5.5
Impact: The sso_util command now accepts passwords from a file
Description: The sso_util command now accepts passwords from a file named in the SSO_PASSWD_PATH environment variable. This enables automated scripts to use sso_util more securely.
-
Tomcat
CVE-ID: CVE-2007-6286, CVE-2008-0002, CVE-2008-1232, CVE-2008-1947, CVE-2008-2370, CVE-2008-2938, CVE-2007-5333, CVE-2007-5342, CVE-2007-5461
Available for: Mac OS X Server v10.5.5
Impact: Multiple vulnerabilities in Tomcat 6.0.14
Description: Tomcat on Mac OS X v10.5 systems is updated to version 6.0.18 to address several vulnerabilities, the most serious of which may lead to a cross site scripting attack. These issues only affect Mac OS X Server systems. Further information is available via the Tomcat site at http://tomcat.apache.org/
-
vim
CVE-ID: CVE-2008-2712, CVE-2008-4101, CVE-2008-2712, CVE-2008-3432, CVE-2008-3294
Available for: Mac OS X v10.5.5, Mac OS X Server v10.5.5
Impact: Multiple vulnerabilities in vim 7.0
Description: Multiple vulnerabilities exist in vim 7.0, the most serious of which may lead to arbitrary code execution when working with maliciously crafted files. This update addresses the issues by updating to vim 7.2.0.22. Further information is available via the vim website at http://www.vim.org/
-
Weblog
CVE-ID: CVE-2008-4215
Available for: Mac OS X Server v10.4.11
Impact: Access control on weblog postings may not be enforced
Description: An unchecked error condition exists in the weblog server. Adding a user with multiple short names to the access control list for a weblog posting may cause the Weblog server to not enforce the access control. This issue is addressed by improving the way access control lists are saved. This issue only affects systems running Mac OS X Server v10.4. Credit: Apple.
Get a WordPress.com Blog
![TUAW [Cafepress]](http://www.blogsmithmedia.com/www.tuaw.com/media/tuaw-cafepress-promo.png)


Reader Comments (Page 1 of 2)
spook4thecia said 6:39PM on 10-09-2008
Does it come with a liscense to kill?
Reply
Nick K. said 6:38PM on 10-09-2008
Installed fine on both my C2D 2GHz Macbook and 1st edition Mac Mini 1.25GHz, both 10.5.5, files were 31.1MB. Zippy 30 second download! :D
Reply
Balls said 6:41PM on 10-09-2008
"Description: A buffer overflow exists in the handling of images with an embedded ICC profile. Opening a maliciously crafted image with an embedded ICC profile may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation of ICC profiles in images. Credit: Apple."
I thought Apple was above buffer overflows?
Reply
Gordon Werner said 6:47PM on 10-09-2008
So in order to run a customized version of PHP with all the bells and whistles ... I had to strip out the 64K code from Apache.
If I install this update ... will I have to do that all over again? or will it leave out the 64K stuff?
Reply
grull27 said 7:17PM on 10-09-2008
Dammit, I have to restart my iMac! >:-(
Reply
Chroma said 7:24PM on 10-09-2008
Wow, it seem like I just installed a security update for my Tiger MacBook Pro. At least Apple is great at supporting the older (Tiger) OS.
Reply
MacPr0 said 8:42PM on 10-09-2008
Beware Mac Pro Users
This update caused my machine to hang at a white screen on restart for about 6 minutes with no disk activity and then spontaneously loaded the login screen. Although I have noticed the update install times increase since I installed Leopard, this update should come with a text file outlining this fact as it may lead less observant users to do a manual reboot before the update is completed.
Reply
Andy said 9:39PM on 10-09-2008
Every app I launch since installing crashes. Even software update and system preferences. I'm running 10.5.5 on a PB G4.
Reply
Philster said 7:24PM on 10-15-2008
@Andy: Did this get resolved?
Any other PowerBook G4 user having problems with this update on 10.5.5?
Tim said 9:10AM on 10-30-2008
Not a PowerBook G4, but an iBook G4 here... and yes I had problems after the install - I couldn't connect to the internet and iTunes couldn't see my AirTunes speakers or my Apple TV after the update... Couldn't find a fix so am currently restoring from a Time Machine backup...
Chase said 10:06PM on 10-09-2008
Andy and MacPr0, you guys are lucky. This update caused my system to stop recognizing my dedicated graphics card on my MacBook Pro 15". The only reason I know about it is because of a wonderful little webapp called logmein. I'm currently controlling my computer from my roommates, and it's working fine, except for the complete and utter lack of a display on the actual screen. I tried plugging in an external display, to no avail. And naturally, Apple's service department is closed for the night. So now I'm trying to reinstall 10.5.5 in hopes that it'll bring back my graphics card as I'm pretty sure that you can't downgrade Security Updates.
Reply
scott said 1:17AM on 10-10-2008
Well, my MacBook Pro is doing okay, but I've had some crazy display issues especially when the screensaver wants to kick in.
Reply
KY said 2:06AM on 10-10-2008
MBP Version 1 here, CoreDuo with 10.5.5. -
updated in less than 5 minutes, without a hitch.
Reply
Atagahi said 5:04AM on 10-10-2008
I had a problem with my sound card icon disappearing from the menu bar and turning off my sound altogether after installing the update. I have a 12" Powerbook G4 1.5 GHz notebook.
I got it working again by rebooting and then unchecking and rechecking the "Show icon" box in the System Preferences pane. It works fine now.
Reply
Dan said 6:57AM on 10-10-2008
It's interesting to note that a majority of the vulnerabilities patched were actually discovered by Apple rather than a 3rd party. It's obvious that Apple wants everybody to know that they're banging on their own stuff, but more importantly fixing it before making an announcement. All you budding security researchers out there look up Responsible Disclosure.
Reply
Mike said 7:35AM on 10-10-2008
Will i have to reboot my Mac then?
Greetz Mike - http://www.torrentfly.org
Reply
Jash Sayani said 7:47AM on 10-10-2008
My Apache config file is screwed !! Hope it gets fixed....
Any way to reset Apache..??
Reply
daven said 8:51AM on 10-10-2008
So..... does this update fix Time Machine since they borked it with the first issue of 10.5.5?
Reply
Lance Fiasconaro said 11:46AM on 10-11-2008
Don't install this if you haven't done so already. Screensaver keeps crashing so that my MBP must be restarted via hard boot. I've also had several other strange kernel hangs in other applications such as Safari.
Reply
Cory said 12:22PM on 10-11-2008
After installing this patch, my video playback (from all sources--QT, iTunes, web-based flash) is "jerky," decidedly not smooth.
For sound, there is absolutely no sound from the iMac speakers--not from iTunes, not from video, not even from the "feedback sound" when I adjust the sound level. The only way to play music from my iMac is to stream it through my AirPort Express.
I can blame it all on Security Update 2008-007.
Reply