Apple releases patch for 13 security flaws
One could allow remote execution of malicious code
TechWorld.com - Apple has warned that the Mac OS X operating system contains 13 security flaws, some of them serious. The company issued a cumulative patch for the bugs today.
The flaws could allow remote code execution, security breaches, spoofing, cross-site scripting, denial-of-service attacks and other problems, according to Apple. Some of the flaws can be exploited from the Internet.
The most serious of the flaws -- including bugs in CoreFoundation and Safari -- could let an attacker remotely execute malicious code, effectively taking over the system. Safari is also vulnerable to less serious attacks, one in which the browser downloads files into a different location, and a spoofing flaw involving JavaScript dialogue boxes.
Other flaws could allow the downgrading of Secure Sockets Layer connections to an earlier, less secure SSL version -- known as a protocol downgrade attack; privilege escalation by local users; a cross-site scripting flaw in Apache; and the ability to forge syslog entries.
Security experts say Apple's security practices have improved but are still at pains to make it clear that Mac OS X isn't as secure as people might think. The SANS Institute last week highlighted Mac security flaws in its list of top 20 security issues, partly in order to give users a wake-up call, according to the organization.
"Although Mac OS X has security features implemented out of the box, such as a built-in personal firewall, unnecessary services turned off by default and easy ways to increase the OS security, the user still faces many vulnerabilities," SANS said in the report.
SANS noted that vulnerabilities continue to crop up regularly in Safari. "In certain cases, exploit code has also been posted publicly," the group said.
Apple's way of releasing updates cumulatively doesn't make things easier for systems administrators, SANS said. "Apple frequently issues Mac OS X cumulative security updates that tend to include fixes for a large number of vulnerabilities with risk ratings ranging from critical to low. This complicates the tracking of vulnerabilities for this OS," SANS's report said.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- VMware View Optimization Guide for Windows 7
- This document provides guidelines for configuring a standard Windows 7 image to be used within a VMware View™ environment, providing administrators with the...
- Watson - A System Designed for Answers. The future of workload optimized systems design
- Watson is a workload optimized system designed for complex analytics, made possible by integrating massively parallel POWER7 processors and DeepQA technology. Read the...
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring... All Operating Systems White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All Operating Systems Webcasts