Sign up for the FREETell Membership and receive benefits that include the digital edition of Tell Magazine sent straight to your inbox, product giveaways, coupons and much more!
Apple today released Security Update 2008-002 for Mac OS X 10.4.11 and 10.5.2.
The update addresses more than 40 known bugs. AppKit, X11, CUPS, and Foundation are the most addressed in the update. Password problems that might show your passwords to other local users were addresses in the areas of Podcaster, Kerberos, Preview, and Printing.
There is also an issue that was addressed with the Image RAW framework. The bug made it possible for someone to send a maliciously crafted image that could cause application shutdowns: “A stack based buffer overflow exists in the handling of Adobe Digital Negative (DNG) image files. By enticing a user to open a maliciously crafted image file, an attacker may cause an unexpected application termination or arbitrary code execution. This update addresses the issue through improved validation of DNG image files. This issue does not affect systems prior to Mac OS X v10.5.”
The update addresses more than 40 known bugs. AppKit, X11, CUPS, and Foundation are the most addressed in the update. Password problems that might show your passwords to other local users were addresses in the areas of Podcaster, Kerberos, Preview, and Printing.
There is also an issue that was addressed with the Image RAW framework. The bug made it possible for someone to send a maliciously crafted image that could cause application shutdowns: “A stack based buffer overflow exists in the handling of Adobe Digital Negative (DNG) image files. By enticing a user to open a maliciously crafted image file, an attacker may cause an unexpected application termination or arbitrary code execution. This update addresses the issue through improved validation of DNG image files. This issue does not affect systems prior to Mac OS X v10.5.”
The update is availabl via Software Update and for download for PowerPC [Regular | Server], Leopard [Regular | Server], and Intel [Regular | Server].
Read [About Security Update 2008-002]
Related Posts