Apple updates Leopard, issues 68 fixes
But it doesn't patch some iCal security bugs
Computerworld - More than three months after it last updated Mac OS X, Apple Inc. today released 10.5.3, an upgrade for its Leopard operating system that boasts nearly 70 stability, compatibility and security improvements and fixes.
Apple did not include patches for two of three iCal vulnerabilities that were made public a week ago, however.
Mac OS X 10.5.3, the third upgrade to Leopard since Apple launched the current in October 2007, addresses issues in several components and bundled applications, ranging from the Address Book and Automator to Time Machine and VoiceOver.
Apple also listed a baker's dozen under a "General" category that included a fix for hard drives that wouldn't show in the Finder; an improvement in Spotlight, the OS's built-in search tool, for searches done on AFP volumes; and a patch for stuttering audio and video playback from certain USB-based hardware.
AirPort, Apple's label for its wireless technology, got a pair of fixes: one to improve wireless reliability in general, the other to boost reliability when used with the company's relatively new Time Capsule router-cum-backup-device that debuted earlier this year.
iChat, the Mac OS's bundled instant messaging and video conferencing application, received five fixes; Mail, Apple's own e-mail client, got 10; and Time Machine was the target of seven.
The Time Machine fixes, said Apple, resolve issues when backing up a notebook running on battery power, and address a reliability problem some users have encountered when restoring from a Time Machine backup.
Apple also tucked eight fixes for iCal, its personal scheduling program, into the 10.5.3 update, but failed to patch two of the three security vulnerabilities disclosed last week by Core Security Technologies.
It appears Apple did patch the most serious of the three -- dubbed CVE-2008-1035 -- which Core said was the only one of the three it had proven could be used to insert malicious code into a Mac.
The three iCal bugs, which were reported to Apple in January 2008, were revealed last Wednesday by Core after it had repeatedly been asked by Apple to delay publishing its findings. Core decided to unveil the vulnerabilities after Apple again postponed its patches.
"No vendor moves as fast as the vulnerability researcher wants them to," said Andrew Storms, director of security operations at nCircle Network Security Inc.
Storms refused to blame either side. "It generally takes a major vendor, like Microsoft or Apple, about six to eight months to get a patch released," he said. "But Core had every right to push the vendor into delivering the patch."
In a follow-on interview last week, Ivan Arce, Core Technologies' chief technology officer, said that the current version of iCal is vulnerable to the flaws, one of which he considered critical. But his team had not found evidence of any in-the-wild attacks trying to trigger the iCal vulnerabilities.
- Best iPhone, iPad Business Apps for 2014
- 14 Tech Conventions You Should Attend in 2014
- 10 Desktop Apps to Power Your Windows PC
- How to Add New Job Skills Without Going Back to School
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
Red Hat Enterprise Linux - The Original Cloud Operating System
Linux adoption is growing against a number of measures, such as the
number of supercomputers that run Linux and the size of the contributing...
- OpenStack Hype vs. Reality: CIO Quick Pulse Open-source architecture can enable IT departments to build infrastructure-as-a-service (IaaS) clouds running on standard hardware.
- Building a Bridge to the Next Generation Data Center Selecting a widely adopted operating system is a foundational component of a standardization strategy.
- OpenStack and Red Hat: IDC White paper Most OpenStack deployments are by public cloud providers that are early adopters of technology and use OpenStack in a do-it-yourself deployment and support...
- Webinar: Building a Big Data solution that's production-ready Big data solutions are no longer just a nice-to-have.
- Meg Whitman presents Unlocking IT with Big Data During this Web Event you will hear Meg Whitman, President and CEO, HP discuss HAVEn - the #1 Big Data platform, as well... All Mac OS X White Papers | Webcasts