You are here: silicon.com > Software > Security Strategy

Security Strategy

Apple plugs 20 OS X holes

Security update deals with Leap.A threat and more...

Tags: flaws, security flaws, leap.a, flaw

By Joris Evers

Published: 2 March 2006 08:20 GMT

Apple on Wednesday released a security update for Mac OS X that fixes 20 vulnerabilities, including a high-profile web browser and Mail flaw disclosed last week.

The set of patches addresses a variety of security flaws, including several that could let an attacker gain control over a computer running the operating system software. The patch arrives after two weeks of intense scrutiny for Apple Mac OS X safety, prompted by the discovery of two worms and the disclosure of two security flaws in that period.

The Apple security update addresses those flaws, which affect the Safari web browser and Apple Mail client. The vulnerabilities expose Mac users to risks that are more familiar to Windows owners: the installation of malicious code through a bad website or email because of improper validation of downloads.

The update also changes iChat, Apple's instant messaging application, to thwart instant message threats such as the Leap.A pest, which was detected recently and attacked some Apple users.

Apple said: "iChat now uses Download Validation to warn of unknown or unsafe file types during file transfers."

Aside from the previously disclosed vulnerability in Safari, the Apple patch fixes four additional security bugs. These could result in code being executed on the user's machine after viewing a malicious website or allow JavaScript to execute in the local domain, Apple said in its update.

Other flaws fixed in the update include four issues related to the PHP scripted programming language, two problems related to Apple's Directory Services, a problem with mounting of file servers and a bug in FileVault secure storage, which was found to be insecure in the way a FileVault image is created.

Security Update 2006-001, can be downloaded and installed via the Software Update feature in Mac OS X or from Apple Downloads.

The representative said: "Apple advises Mac OS X users to keep their system current by installing this and all Mac OS X software updates."

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...

Naked CIO Naked CIO: Cloud computing more expensive than we thought? Smart IT leaders will examine the impact of how they pay for tech


  • Jobs
Front-end and SEO Developer Macclesfield 30,000

To apply my client is looking for proven skills in JavaScript, using it for basic animation, form validation XHTML, writing XHTML to a hand-coding ...

C# Web Developer - London - to 55k

XHTML and CSS * Knowledge of accessibility and W3C * Strong customer focus and experience defining the structure of user interfaces and defining ...

Software Engineers - Apple Safari

Apple Safari Contract or Permanent Software Engineers for Entrepreneurial Telecoms Start-up My client is a start-up communications software company ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: