HZFQ.COM
welcome to my space
X
Welcome to:hzfq.com
Search:  
NAVIGATION - HOME
Apple Patches Flawed Leopard, Tiger
Published by: jane 2008-11-20

Apple fixes DNS flaw in Mac OS X | Software Journal::
Apple has finally issued their patches for the DNS flaws in both Mac OS X Tiger and Leopard. Apple, DNS, Mac OS X, Mac OS X Leopard, Mac OS X Tiger,
http://stuff.techwhack.com/4267-dns-flaw
HOME
Apple has patched its Mac 10.5 Leopard for the second time in its young life. Meanwhile, its older sibling, Mac OS 10.4 Tiger, will also get its share of fixes.

In total, the vulnerabilities are serious enough that the United States Computer Emergency Readiness Team (US-CERT) has issued a Technical Cyber Security Alert.

"The impacts of these vulnerabilities vary," US-CERT's alert states. "Potential consequences include arbitrary code execution, sensitive information disclosure, and denial of service."

Among the fixes for Tiger is a patch for Service Location Protocol, or SLP (define), which was at risk from stack buffer overflow. Apple admits in its advisory that the issue was first reported more than a year ago as part of January 2007's Month of Apple Bugs.

Though the issue is a long-standing one, the actual impact of the bug is relatively limited. Apple notes that if a hacker exploits the flaw, a local user may be able to take advantage by executing arbitrary code with system privileges.

AppleInsider | Apple patches QuickTime flaw, issues Security and ::
Apple updates iTunes, QuickTime, Front Row. Apple releases QuickTime 7.4.1 for Leopard, various components of Apples Mac OS X 10.4 Tiger operating system.
http://www.appleinsider.com/articles/07/05/01/apple_patche_and_airport_updates.html
HOME
Tiger also gets a fix for an issue with its Mail application.

"An implementation issue exists in Mail's handling of file:// URLs, which may allow arbitrary applications to be launched without warning when a user clicks a URL in a message," Apple's advisory states.

Apple's fix for Mail is simple: Don't launch the file on click -- just show the location of the file.

For Leopard, Apple has fixed a critical memory-corruption issue that affects its Safari Web browser. If a user visits a specially constructed URL, arbitrary code execution or a system crash could result.

Apple has fixed the issued in 10.5.2 by using additional URL validations.

The Leopard update also includes a fix for Apple's parental controls, which is supposed to limit access based on specified settings. The flaw does not lead to arbitrary code execution but rather to an involuntary information disclosure to Apple.

"When set to manage Web content, the parental controls will inadvertently contact www.apple.com when a Web site is unblocked," Apple states in its advisory. "This allows a remote user to detect the machines running Parental Controls."

In addition to issues for which Apple holds responsibility, the fixes resolve problems in X.org's open source X11 graphical user interface.

One fix for Samba is a critical open source technology that allows Windows print and file sharing on Unix-based operating systems.

The 10.5.2 update is the first for the core Leopard OS since December, when 10.5.1 plugged some 31 security vulnerabilities.

Earlier this month Apple patched its often-attacked QuickTime media player, fixing a media-streaming protocol issue unresolved in its January 7.4 update.


Confirmed: Microsoft and Facebook Friendship
Red Hat Expands Legal Firepower

You are looking at:hzfq.com's Apple Patches Flawed Leopard, Tiger, click hzfq.com to home

#If you have any other info about this subject , Please add it free.#
Your name:
E-mail:
Telphone:

Your comments:


If you have any other info about Apple Patches Flawed Leopard, Tiger , Please add it free.

About us -Site map -Advertisement -Jion us -Contact usExchange linksSponsor us
Copyright© 2008 hzfq.com All Rights Reserved
Site made&Support support@hzfq.com    E-mail: web@hzfq.com