For the second time this month, Apple has released security patches to correct vulnerabilities found in several versions of its Mac OS X.
A "moderately critical" vulnerability in two Apache modules, mod_alias and mod_rewrite, could conceivably give a network user escalated privileges or let them launch a denial-of-service attack (define). Security officials also modified how the mod_cgid communicates with CGI script,
saying it was not "handled properly."
Slashdot | Apples Colossal Disappointment?:: they are entirely without flaw, but stepping into a Apple Store it should be The app itself would be a binary, fat only if compiled for multiple http://apple.slashdot.org/article.pl?sid=05/07/26/2043200&from=rssHOME | Apple also patched an unspecified vulnerability in the SystemConfiguration subsystem that allows network admins to change network settings and system configuration. Unspecified vulnerabilities were also found in the Mac OS X mail application, Safari Web browser, Windows file sharing and in the environment variables area.
Oracle looking at emergency patch for WebLogic - Network World:: The problem lies in an Apache plug-in for WebLogic and is rated a 10 in severity. running on Windows, Linux and Apples Mac OS X. The flaws could allow a http://www.networkworld.com/newsletters/bug/2008/072808bug2.htmlHOME | Fixes have been issued for Mac OS X versions: 10.3.2 client and server; 10.2.8 client and server; and 10.1.5 client and server and can be found here.
Earlier this month, Apple patched a lower-priority vulnerability in the code that allowed a local user to "crash" SecurityServer by inputting a long password into a keychain. Several applications in Mac OS X cannot operate without SecurityServer, causing a denial of service.
Items Tagged With applesucks:: First iPhone 3rd Party GUI App Compiles. Jail-Breaking iPhones at the Apple Store iPhone Can Now Run Apache, Python, Vim. iPhone Keyboard Leads to Typso http://apple.slashdot.org/tags/applesucksHOME | Apache upgrade released to fix security hole | ITworld:: A flaw has been discovered in the newest version of the Apache Web server that Apple broadband cell phone Chrome Dell Facebook Firefox Google Google Apps http://www.itworld.com/020819apacheupgradeHOME |
Gov't Rolls Out Cyber Alert System
MyDoom Virus Could be 'Linux War' Weapon
|