Apple fixes Flash snafu in Snow Leopard, patches 33 bugs in Leopard
Mac users get third and fourth updates this week, but Safari may be next, says researcher
Computerworld - Less than two weeks after Apple launched Snow Leopard, the company today issued the new operating system's first security update. In a separate upgrade, Apple patched 33 vulnerabilities in 2007's Leopard, and about half as many in the even older Tiger.
Today's updates were the third and fourth from Apple in the last two days. Wednesday, Apple delivered security fixes for the iPhone and iPod Touch, as well as another upgrade for its QuickTime media player.
"It's another sneak attack," said Andrew Storms, director of security operations at nCircle Network Security, referring to the string of updates. "Actually, it's almost what we've come to expect from Apple," he added. Unlike rival OS maker Microsoft, which releases most of its security upgrades on a pre-set monthly schedule, Apple ships its patches whenever they're ready to go out the door.
The Snow Leopard 10.6.1 update's security content consisted solely of an upgrade for Adobe's Flash Player, which was bumped to the up-to-date version 10.0.32.18.
Users and security researchers had taken Apple to task for not only shipping Snow Leopard with an outdated and vulnerable version of Flash Player, but also for silently "downgrading" once-secure editions when Macs were updated to the new operating system.
Mac OS X 10.6.1 packaged nine patches for Flash vulnerabilities, some of which could result in "arbitrary code execution," Apple-speak of a critical flaw that attackers could exploit to grab control of a Mac. According to the corresponding Adobe security advisory, six of the nine flaws could be considered critical.
Apple released the first update for Snow Leopard less than two weeks after it debuted the operating system on Aug. 28, a slightly faster pace than in 2007, when Apple took about three weeks to issue the first security update for Mac OS X 10.5, aka Leopard.
Adobe updated Flash Player to 10.0.32.18 in late July to plug a dozen vulnerabilities, including three inherited from flawed Microsoft development code -- obviously, those were not present in the Mac version -- and one that hackers had been exploiting for at least a week, which did apply to the Mac.
"Having to release a whole OS update just to patch one third-party component, that's a bit heavy-handed," said Storms. "Apple had to go through one whole engineering cycle to fix Flash."
As if to echo Storms' point, Apple noted that the 10.6.1 update -- which admittedly includes fixes for eight non-security issues -- tipped the scale at 75MB.
The Security Update 2009-005 for Leopard and Tiger was more traditional, patching 33 vulnerabilities in the former and 16 in the latter. Of the 33 bugs in Mac OS X 10.5, Leopard, 23 were tagged with Apple's "arbitrary code execution" phrase; 14 of the 16 flaws in Tiger were pegged the same way.
Mac OS X Snow Leopard
- Apple signals end to OS X Snow Leopard support
- Apple sneaks Safari update into Snow Leopard
- OS X Snow Leopard stubbornly rejects retirement
- Snow Leopard users: Just try to pry this from my cold, dead hands
- Apple goes against grain, extends support for Snow Leopard
- Mac users left wondering if OS X Snow Leopard's retired
- Opinion: In depth with Apple's Snow Leopard Server
- Apple fixes data deletion bug in Snow Leopard, blocks Atom 'hackintoshes'
- Smackdown: Windows 7 takes on Apple's Snow Leopard
- Snow Leopard sales roar out the gate
- 15 Non-Certified IT Skills Growing in Demand
- How 19 Tech Titans Target Healthcare
- Twitter Suffering From Growing Pains (and Facebook Comparisons)
- Agile Comes to Data Integration
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- Is Your Big Data Solution Production-Ready? Read "Is Your Big Data Solution Production-Ready?" now, and discover best practices and actionable steps to implementing a production-ready big data solution.
- Pay-as-you-Grow Data Protection: IBM Tivoli's Full-featured Data Protection Suite for Small to Medium Businesses IBM Tivoli Storage Manager Suite for Unified Recovery gives small and medium businesses the opportunity to start out with only the individual solutions...
- Streamline Data Protection with IBM Tivoli Storage Manager Operations Center IBM Tivoli Storage Manager (TSM) has been an industry-standard data protection solution for two decades. But, where most competitors focus exclusively on Backup...
- Simplify and Consolidate Data Protection for Better Business Results Learn about IBM® Tivoli® Storage Manager Operations Center, which provides advanced visualization, built-in analytics and integrated workflow automation features that leapfrog traditional backup...
- Webinar: Building a Big Data solution that's production-ready Big data solutions are no longer just a nice-to-have.
- Meg Whitman presents Unlocking IT with Big Data During this Web Event you will hear Meg Whitman, President and CEO, HP discuss HAVEn - the #1 Big Data platform, as well... All Mac OS X White Papers | Webcasts