Thursday, February 12, 2009, 02:10 pm PT (05:10 pm ET)
Apple fixes Safari RSS vulnerability, updates JavaApple on Thursday afternoon released Security Update 2009-001 that, among other fixes, tackles the Safari RSS vulnerability made public last month. Also, a Java for Mac OS X update delivers security and compatibility improvements for users running Leopard or Tiger.
Security Update 2009-001
The new update is available in many flavors through Software Update for Leopard (43.4MB), Server Universal (213MB), Tiger PowerPC (74MB), Leopard Server (46.54MB), Tiger Server PowerPC (141.76MB), and Tiger Intel (164.23MB).
According to Apple, the update fixes the security flaw found in Safari last month that opened the door to malicious websites accessing personal information through an RSS feed.
Other fixes are enclosed for vulnerabilities in the X11 server, AFP server, Apple Pixlet Video, a memory corruption issue in CarbonCore, and a flaw where local users could access another user's deleted, then recreated, Downloads folder, to name a few.
Tiger-specific vulnerabilities repaired with the round of fixes were found in FreeType and LibX11. According to the document, computers running Leopard are either not affected by these two issues or have already been fixed in Mac OS X 10.5.6.
Apple Support has the full release notes.
Java for Mac OS X 10.5 Update 3, 10.4 Release 8
Leopard users are asked to install Java for Mac OS X 10.5 Update 3 (3MB), which improves the security and compatibility of Java on Mac OS X 10.5.6 and later.
Details are few, but Apple says the release updates the Java Web Start and Java Applet components.
Users of Apple's older Tiger release are being given Java for Mac OS X 10.4 Release 8 (1.6MB) through Software Update to update the same Web Start and Applet components in the earlier software.
On Topic: Mac OS X
- Apple, Inc's double digit U.S. Mac growth contradicts IDC & Gartner reports of a Mac sales slump
- Public beta launch nearly doubles OS X 10.10 Yosemite adoption despite download issues
- Apple makes first OS X Yosemite public beta available on the Mac App Store
- Apple issues new Safari betas for OS X Mavericks, Mountain Lion with minor changes
- Apple to release first public beta of OS X Yosemite on Thursday