Security Update 2010-005 now available
Security Update 2010-005 is now available and addresses the
following:
ATS
CVE-ID: CVE-2010-1808
Available for: Mac OS X v10.5.8, Mac OS X Server v10.5.8,
Mac OS X v10.6.4, Mac OS X Server v10.6.4
Impact: Viewing or downloading a document containing a maliciously
crafted embedded font may lead to arbitrary code execution
Description: A stack buffer overlow exists in Apple Type Services'
handling of embedded fonts. Viewing or downloading a document
containing a maliciously crafted embedded font may lead to arbitrary
code execution. This issue is addressed through improved bounds
checking.
CFNetwork
CVE-ID: CVE-2010-1800
Available for: Mac OS X v10.6.4, Mac OS X Server v10.6.4
Impact: An attacker with a privileged network position may intercept
user credentials or other sensitive information
Description: CFNetwork permits anonymous TLS/SSL connections. This
may allow a man-in-the-middle attacker to redirect connections and
intercept user credentials or other sensitive information. This issue
does not affect the Mail application. This issue is addressed by
disabling anonymous TLS/SSL connections. This issue does not affect
systems prior to Mac OS X v10.6.3. Credit to Tomas Bjurman of Sirius
IT, Jean-Luc Giraud of Citrix, and Aaron Sigel of vtty.com for
reporting this issue.
ClamAV
CVE-ID: CVE-2010-0098, CVE-2010-1311
Available for: Mac OS X Server v10.5.8, Mac OS X Server v10.6.4
Impact: Multiple vulnerabilities in ClamAV
Description: Multiple vulnerabilities exist in ClamAV, the most
serious of which may lead to arbitrary code execution. This update
addresses the issues by updating ClamAV to version 0.96.1. ClamAV is
distributed only with Mac OS X Server systems. Further information is
available via the ClamAV website at http://www.clamav.net/
CoreGraphics
CVE-ID: CVE-2010-1801
Available for: Mac OS X v10.5.8, Mac OS X Server v10.5.8,
Mac OS X v10.6.4, Mac OS X Server v10.6.4
Impact: Opening a maliciously crafted PDF file may lead to an
unexpected application termination or arbitrary code execution
Description: A heap buffer overflow exists in CoreGraphics' handling
of PDF files. Opening a maliciously crafted PDF file may lead to an
unexpected application termination or arbitrary code execution. This
issue is addressed through improved bounds checking. Credit to
Rodrigo Rubira Branco from the Check Point Vulnerability Discovery
Team (VDT) for reporting this issue.
libsecurity
CVE-ID: CVE-2010-1802
Available for: Mac OS X v10.5.8, Mac OS X Server v10.5.8,
Mac OS X v10.6.4, Mac OS X Server v10.6.4
Impact: An attacker in a privileged network position who can obtain
a domain name that differs only in the last characters from the name
of a legitimate domain may impersonate hosts in that domain
Description: An issue exists in the handling of certificate host
names. For host names containing three or more components, the last
characters are not properly compared. In the case of a name
containing exactly three components, only the last character is not
checked. For example, if an attacker in a privileged network position
could obtain a certificate for www.example.con the attacker can
impersonate www.example.com. This issue is addressed through improved
handling of certificate host names. Credit to Peter Speck for
reporting this issue.
PHP
CVE-ID: CVE-2010-1205
Available for: Mac OS X v10.6.4, Mac OS X Server v10.6.4
Impact: Loading a maliciously crafted PNG image may lead to an
unexpected application termination or arbitary code execution
Description: A buffer overflow exists in PHP's libpng library.
Loading a maliciously crafted PNG image may lead to an unexpected
application termination or arbitary code execution. This issue is
addressed by updating libpng within PHP to version 1.4.3. This issue
does not affect systems prior to Mac OS X v10.6.
PHP
CVE-ID: CVE-2010-1129, CVE-2010-0397, CVE-2010-2225, CVE-2010-2531,
CVE-2010-2484
Available for: Mac OS X v10.6.4, Mac OS X Server v10.6.4
Impact: Multiple vulnerabilities in PHP 5.3.1
Description: PHP is updated to version 5.3.2 to address multiple
vulnerabilities, the most serious of which may lead to arbitary code
execution. Further information is available via the PHP website at
http://www.php.net/
Samba
CVE-ID: CVE-2010-2063
Available for: Mac OS X v10.5.8, Mac OS X Server v10.5.8,
Mac OS X v10.6.4, Mac OS X Server v10.6.4
Impact: An unauthenticated remote attacker may cause a denial of
service or arbitrary code execution
Description: A buffer overflow exists in Samba. An unauthenticated
remote attacker may cause a denial of service or arbitrary code
execution by sending a maliciously crafted packet. This issue is
addressed by performing additional validation of packets in Samba.
Security Update 2010-005 may be obtained from the Software Update
pane in System Preferences, or Apple's Software Downloads web site:
http://www.apple.com/support/downloads/
For Mac OS X v10.6.4
The download file is named: SecUpd2010-005Snow.dmg
Its SHA-1 digest is: 0f849caddd3b61383dabf423848f9f8059f4656e
For Mac OS X Server v10.6.4
The download file is named: SecUpdSrvr2010-005.dmg
Its SHA-1 digest is: 0a089a7c367ae2f38149ad1f535cc5ff078d3f15
For Mac OS X v10.5.8
The download file is named: SecUpd2010-005.dmg
Its SHA-1 digest is: 22912e8c3756c03ea7565c7689b05952bae0bb50
For Mac OS X Server v10.5.8
The download file is named: SecUpdSrvr2010-005.dmg
Its SHA-1 digest is: f2accfece4593b7a2658f65b2076c3b83227ff8c
Information will also be posted to the Apple Security Updates
web site: http://support.apple.com/kb/HT1222
Share
Categories
Gather up the kids and press the software update button: the latest Security Update (2010-005) for Mac OS X 10.5 and 10.6 is now on the...
Add a Comment
I've having a hell of a time with keychain passwords since installing this security update. Specifically with my MobileMe account. Anyone else experiencing this?
August 25 2010 at 4:28 PM Report abuse Permalink rate up rate down Replythe 10.6.4 update was a disaster for me. The nasty OpenGL bug that caused (and still causes, to my understanding) those of us with NVIDIA cards to have massive lock-ups, still hasn't been fixed. WTF Apple?
August 24 2010 at 11:18 PM Report abuse Permalink rate up rate down ReplyIs there a 10.6.4 release? That's what it showed for me?
August 24 2010 at 11:05 PM Report abuse Permalink rate up rate down ReplyInstalled this update, rebooted. Left it on login screen, closed the lid. Opened it back up later and the screen's backlight wouldn't come on. This has happened before on Windows through Boot Camp but never in OSX. Hope it's a fluke and not going to be a semi-regular thing.
August 24 2010 at 8:53 PM Report abuse Permalink rate up rate down ReplyYuck. Another reboot. Lately when I have to do this, the computer comes back on December 31, 2000, with a slew of error messages and unanswerable demands for decisions about allowing indecipherable programs to access the web. It's very like Microsoft.
August 24 2010 at 8:37 PM Report abuse Permalink rate up rate down ReplySounds like your motherboard battery or PRAM may be wonky. You may want to visit the Genius Bar.
August 24 2010 at 9:10 PM Report abuse Permalink rate up rate down ReplyThis also happened to me. Also had problems with keychain not recognising my wifi, mobileMe account etc. Did a full shutdown and restarted my MacBook Pro and everything seems to working OK now. It's the first update I've ever run that caused me any concern though
August 25 2010 at 5:28 PM Report abuse Permalink rate up rate down ReplyAfter this Update my Dock (Magnification/Hiding/Animations) & MouseOver-Things doesnt work anymore.
(Even after some restarts)
Macbook Pro 13" (2010)
Any tips?
I had the same issue.... PRAM reset resolve it (Press and hold the Command-Option-P-R keys )
August 25 2010 at 6:06 PM Report abuse Permalink rate up rate down ReplyThanks.. worked fine! :)
August 25 2010 at 6:52 PM Report abuse Permalink rate up rate down ReplyInstalled it and my MBP15 rebooted without problems. As Jimbo already pointed out all viruses are gone :)
August 24 2010 at 5:25 PM Report abuse Permalink rate up rate down ReplyInstalled this one a bit ago. Ever since then, I've had no viruses or malware... ;-)
August 24 2010 at 5:15 PM Report abuse Permalink rate up rate down ReplyHot Apps on TUAW
Deals of the Day
more deals- Wicked Jaw Breaker Noise-Isolating In-Ear Headphones for $6 + free shipping
- Refurb Apple MacBook Air Laptops: 12" 64GB SSD for $699 + free shipping
- JVC Motion Sensing Clock Radio with Dual iPod Docks for $55 + free shipping
- Apple iPhone Headset with Mic for $4 + $2 s&h
- Refurb Apple iPod nano 8GB MP3 Player for $99 + free shipping, 16GB for $119
- Hannspree Apple-Shaped 28" 1080p LCD HDTV for $270 + free shipping
Software Updates
more updates- EFI Firmware Update brings Lion Internet Recovery to 2010-model Macs
- OS X Lion 10.7.3 released with Safari 5.1.3, Wi-Fi bug fix
- Aperture updated to 3.2.2, addresses Photo Stream issue
- Apple updates Keynote to address Lion issues
- Google Search app gets new look on iPad
- Apple releases Apple TV Software Update 4.4.3




12 Comments