internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Internet Explorer 8

Most Popular Software Downloads
Opera
Internet Explorer 7
QuickTime for Windows
Winamp
Mozilla Firefox 3
Ad-Aware 2008 Free
Adobe Flash Player
Paint Shop Pro
Adobe Shockwave Player
AVG Anti-Virus Free
7-Zip

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

Apple Patches Tiger and Leopard
Tiger, Leopard, Safari, and QuickTime All Receive Security Fixes
Sean Michael Kerner

Apple Mac users: It's time to patch your systems. Yes, again, after a whole lot of patches this year.

Security Update 2007-009 from Apple provides updates for both OS 10.4 Tiger as well as the new OS 10.5 Leopard. In total there are 31 fixes for issues ranging in severity from information disclosure to arbitrary code execution. As an added bonus, if you're running Apple's Safari browser for Windows XP or Vista, you also need to update.

Among the issues fixes are three that deal with Apple's use of CUPS (Common UNIX Printing System) CUPS>. For both Tiger and Leopard users, a memory corruption issue that could enable an attacker to crash a system or execute arbitrary code.

Another issue with CUPS for just Tiger involves the use of SNMP (define) (Simple Network Management Protocol). According to Apple's advisory on the issue, "The CUPS back-end SNMP program broadcasts SNMP requests to discover network print servers. A stack buffer overflow may result from an integer underflow in the handling of SNMP responses." As a result, a crash or arbitrary code could be executed.

A third issue with CUPS that affects Tiger is a buffer overflow condition that is within the printer driver itself. The impact of this flaw could be privilege escalation.

Apple has also fixed its iChat instant messaging application in Tiger. According to Apple's advisory, "a person on the local network may initiate a video connection without the user's approval." Apple has resolved the issue by simply adding in a user request in order to start a video conference.

There are also a lot of fixes for dynamic languages in Apple's update including new versions of Perl, Python and Ruby.

For Leopard, which was just updated a month ago to version number 10.5.1, there is a fix for the Software Update mechanism itself. Apple's advisory describes a situation whereby by when the Software Update checks Apple's repository for updates there is a possibility for a man-in-the-middle attack.

"By intercepting requests to the update server, an attacker can provide a maliciously crafted distribution definition file with the "allow-external-scripts" option, which may cause arbitrary command execution when a system checks for new updates," Apple's advisory states.

The Safari web browser for Tiger, Leopard as well as Windows XP and Vista gets patched in this update for an information disclosure issue. The vulnerability is due to the way the browser allows pages to navigate the subframes of other pages which could be used in a cross site scripting (XSS) scenario to get a users information.

The 007-009 security update is Apple's first that deals with both Tiger and Leopard. Tiger was last updated to version 10.4.11 in mid-November with 40 fixes. Apple has been busy this year patching its QuickTime software as well patching the media software last week to version 7.3.1 for a variety of serious flaws.

News courtesy of internetnews.com

December 18, 2007

Download Safari for Windows Now!Download

Download QuickTime for Windows Now!Download

Contents:
1. Tiger, Leopard, Safari, and QuickTime All Receive Security Fixes


Additional Articles:

  • Apple Fine-Tunes Software Amid Concerns
  • Who's King of the Browser Speed Jungle?


  • internet.comearthweb.comDevx.commediabistro.comGraphics.com

    Search:

    Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

    Jupitermedia Corporate Info

    Legal Notices, Licensing, Reprints, Permissions, Privacy Policy.
    Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

    Whitepapers and eBooks

    Symantec Whitepaper: Converging System and Data Protection for Complete Disaster Recovery
    Intel Whitepaper: Comparing Two- and Four-Socket Platforms for Server Virtualization
    IBM Solutions Brief: Go Green With IBM System xTM And Intel
    HP eBook: Simplifying SQL Server Management
    IBM Contest: Are You the Next Superstar? Join the "Search for the XML Superstar" Contest to Find Out
    Intel PDF: Quad-Core Impacts More Than the Data Center
    Intel PDF: Virtualization Delivers Data Center Efficiency
    Go Parallel Article: PDC 2008 in Review
    Avaya Article: Communication-Enabled Mashups: Empowering Both Business Owners and IT
    Intel Whitepaper: Building a Real-World Model to Assess Virtualization Platforms
    PDF: Intel Centrino Duo Processor Technology with Intel Core2 Duo Processor
    Microsoft Article: Build and Run Virtual Machines with Hyper-V Server 2008
      Go Parallel Article: Q&A with a TBB Junkie
    IBM Whitepaper: Innovative Collaboration to Advance Your Business
    Internet.com eBook: Real Life Rails
    IBM eBook: The Pros and Cons of Outsourcing
    Internet.com eBook: Best Practices for Developing a Web Site
    IBM CXO Whitepaper: The 2008 Global CEO Study "The Enterprise of the Future"
    Avaya Article: Call Control XML in Action - A CCXML Auto Attendant
    IBM CXO Whitepaper: Unlocking the DNA of the Adaptable Workforce--The Global Human Capital Study 2008
    Adobe Acrobat Connect Pro: Web Conferencing and eLearning Whitepapers
    Symantec Whitepaper: Comprehensive Backup and Recovery of VMware Virtual Infrastructure
    MORE WHITEPAPERS, EBOOKS, AND ARTICLES