Apple Inc. on Thursday issued a security update that stomps out four critical flaws within its Mac OS X operating system, all of which were first revealed last month as part of the "Month of Apple Bugs" project run by independent security analysts.
The first fix targets a vulnerability that left iChat's Bonjour wireless discovery open to an attack that could result in an application crash. Meanwhile, the second patches a format string vulnerability in the software's URL handler that could have allowed attackers to trigger an overflow, which could then lead to an application crash or arbitrary code execution.
Apple said it addressed the issues by performing additional validation of both Bonjour messages and AIM URLs.
The Mac maker also bandaged a memory corruption vulnerability in the Mac OS X Finder that could be triggered by a disk image containing a volume name longer than 255 bytes. The issue, which could lead to an exploitable denial of service condition and potential arbitrary code execution, was repaired through additional validation checks, the company said.
Of all the bugs targeted by the Apple security update, one that was capable of using the Mac OS X notification process to hijack root access may have posed the greatest danger to users. Apple said the issue was repaired by making the UserNotificationCenter software process drop its group privileges immediately after launching.
18 Comments
It's about time!
I really don't feel it took THAT long. 2 weeks is pretty quick IMO to figure out how to fix it, develop it, test it, release it.
Apple Inc. on Thursday issued a security update that stomps out four critical flaws within its Mac OS X operating system, all of which were first revealed last month as part of the "Month of Apple Bugs" project run by independent security analysts.
I can't believe it! No... can't be!
Only Windows OS has security flaws... OSX is built on UNIX and is perfectly secure... what a bunch of bull!
Who said that Mac OS X was "perfectly" secure? Do you have a quote for that?
Who said that Mac OS X was "perfectly" secure? Do you have a quote for that?
God did. ... Come on that's funny. I love it when people tell me "God told them".