Apple delivers record monster security update
Patches 92 bugs in Leopard, Snow Leopard; no fix for Pwn2Own vulnerability
Computerworld - Apple today patched 92 vulnerabilities, a third of them critical, in a record update to its Leopard and Snow Leopard operating systems.
Security Update 2010-002 plugged 92 holes in the client and server editions of Mac OS X 10.5 and Mac OS X 10.6, breaking a record that has stood since March 2008. The update dwarfed any released last year, when Apple's largest patched 67 vulnerabilities.
"The sheer number, it's almost so daunting that you don't even want to look," said Andrew Storms, director of security operations at nCircle Network Security.
Today's security roll-up fixed flaws in 42 different applications or operating system components in Mac OS X, from AppKit and Application Firewall to unzip and X11, the Mac's version of the X Window System.
Eighteen of the vulnerabilities were specific to the older Leopard operating system, while 29 were specific to Snow Leopard. The remaining 45 affected both, which are the only editions that Apple currently supports. Users running Leopard will patch 63 vulnerabilities, while Snow Leopard users face a total of 74 flaws.
The update brings Snow Leopard to version 10.6.3, making this the third major update to the OS that Apple launched in August 2009. Apple also addressed a list of nearly 30 non-security issues in the 10.6.3 update. Leopard users, meanwhile, received only the security patches.
More than 40% of the vulnerabilities patched today, 37 out of the 92, were accompanied by the phrase "may lead to arbitrary code execution," which is Apple's way of saying that a flaw is critical and could be used by attackers to hijack a Mac. Apple does not assign ratings or severity scores to the bugs it patches, unlike other major software makers, such as Microsoft and Oracle.
Among the most noticeable patches were nine affecting QuickTime, Apple's media player, in Snow Leopard. All nine were rated critical; six had been reported to Apple by 3Com TippingPoint, which runs a bug bounty program called Zero Day Initiative.
TippingPoint was in the news much of last week as it again sponsored the Pwn2Own hacking contest at the CanSecWest security conference in Vancouver, British Columbia. The company handed out $45,000 in prizes to five researchers for hacking the iPhone, as well as Apple's Safari, Microsoft's Internet Explorer and Mozilla's Firefox browsers.
Charlie Miller, the researcher who cracked Snow Leopard's security defenses to take down Safari, said today that Apple had not patched the vulnerability he used last Wednesday. "New patch doesn't fix pwn2own bug," Miller said via Twitter. "Sorry suckers, gonna have to wait for the next patch."
The timing of today's monster update didn't come as a surprise to nCircle's Storms. "It's not suprising that they patched QuickTime, what with the pending iPad release," he said today, referring to the April 3 on-sale date for Apple's new media tablet. Apple typically updates its iTunes music software, and the accompanying QuickTime player, before it releases new products that call on the former. The iPad will use the iTunes store to serve up applications and media content to customers.
"For the same reason, I'm going to guess that Apple will also update the iPhone OS this week," Storms added.
The security update can be downloaded from the Apple site or installed using Mac OS X's integrated update service.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at
@gkeizer or subscribe to Gregg's RSS feed
. His e-mail address is gkeizer@ix.netcom.com.
Apple Watch
- Apple to build Macs in low-tax Texas
- Apple breaks into Fortune 500's top 10
- Apple hijacks OS X devs to keep iOS on track
- Think different: Apple's $17B debt offers stark contrast to 1996's junk bonds
- To give back to investors, Apple goes for massive bond deal
- Yes Siri, no Siri, for the Mac
- Moves, mistakes prove Steve Jobs era at Apple over, say analysts
- Apple's WWDC sells out in under 3 minutes
- Apple CEO defends Mac line; analysts foresee iPad hybrids
- Apple's WWDC set for June 10-14, hints at fall launch of next iPhone
Read more about Security in Computerworld's Security Topic Center.
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- IDC Security Infographic From the Era Before security to this current era of empowerment this infographic from Blue coat provides a timeline navigates the rise of...
- Key Drivers: Why CIOs Believe Empowered Users Set the Agenda for Enterprise Security Several years ago, a transformation in IT began to take place; a transformation from an IT-centric view of technology to a business-centric view...
- Security Empowers Business Every magazine article, presentation or blog about the topic seems to start the same way: trying to scare the living daylights out of...
- Business Assureance Technology Infographic IT Leaders See security as barrier to enabling employees. However with new Business assurance technology you are able to give Continuity, Agility, and...
- Live Webcast
Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider - Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider
- Live Webcast
MFT and FileXpress - An Overview - Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity.
- Live Webcast
Bridging HTTP and FTP with FileXpress Internet Server - What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts
