Apple fixes irritating Mountain Lion bugs, firms up Java defenses
Keeps 25% of Mac users happy by continuing to patch 2009's Snow Leopard
Computerworld - Apple on Tuesday updated OS X Mountain Lion, likely for one of the last times, with a combination of compatibility and reliability bug fixes as well as vulnerability patches.
The update to OS X 10.8.4 -- the first from Apple since mid-March -- was accompanied by security-only updates for both OS X 10.7, aka Lion, and OS X 10.6, better known as Snow Leopard.
Mountain Lion received at least 16 non-security bug fixes -- the number Apple called out in an advisory -- ranging from improved Calendar-to-Exchange server synchronization to allowing FaceTime video calls to non-U.S. phone numbers. A pair of fixes improved the reliability of connecting to workplace Wi-Fi networks, while others dealt with irritating issues including Macs' refusal to go into sleep mode after having run Boot Camp and a habit of its chat and texting client to mix up the order of messages.
On the security side, OS X 10.8.4 patched 31 vulnerabilities in Mountain Lion, 17 of which were labeled with the phrase "may lead to ... arbitrary code execution," Apple's way of saying the bug was critical.
A majority of the patches were aimed at open-source components integrated with Mountain Lion, such as OpenSSL (13 patches) and Ruby (8), an open-source implementation of SSL encryption and a programming language, respectively. Another four patches quashed bugs in Apple's own QuickTime media player.
One of the OpenSSL patches disabled the protocol's compression to block hacks -- Apple acknowledged that there were "known attacks" -- using techniques revealed last September by a pair of security researchers. Dubbed CRIME, the attack can decrypt session cookies from supposedly-secure HTTPS connections.
Apple listed the two researchers who came up with CRIME, Juliano Rizzo and Thai Duong, in its advisory.
Also tucked into 10.8.4 was a change in how OS X handles Java Web Start applets, yet another attempt by Apple to stymie an increasing number of attacks leveraging Java vulnerabilities.
"Starting with OS X 10.8.4, Java Web Start applications downloaded from the Internet need to be signed with a Developer ID certificate," Apple said. "Gatekeeper will check downloaded Java Web Start applications for a signature and block such applications from launching if they are not properly signed."
Gatekeeper is a Mountain Lion-only security tool designed to bar the installation of malware by requiring programs of all kinds to be digitally signed. By default, only software downloaded from the Mac App Store or signed with certificates Apple provides to registered developers can be installed on Mountain Lion.
- Researcher claims two hacker gangs exploiting unpatched IE bug
- Update: Third of Internet Explorer users at risk from attacks
- Microsoft plans another short patch slate for next week, but finds a few XP bugs to crush
- Target attack shows danger of remotely accessible HVAC systems
- Target hackers try new ways to use stolen card data
- Update: Microsoft to patch just-revealed Windows zero-day tomorrow
- NSA spying prompts open TrueCrypt encryption software audit to go viral
- Microsoft warns of Office zero-day, active hacker exploits
- Hackers move to create next Blackhole after 'Paunch' arrest
- Adobe hack shows subscription software vendors lucrative targets
- Radicati: Cloud Business Email - Market Quadrant 2013 Google was named the top cloud business email provider in a recent report by research firm Radicati. Out of 14 key players, Google...
- Tablets in the Enterprise: A Checklist for Successful Deployment How can you enterprise manage and secure tablets in order to protect corporate data while providing access to the information and applications employees...
- Enterprise Mobility: A Checklist for Secure Containerization The advantages and disadvantages of the multiple approaches to containerization. Learn More>>
- Enterprise File Sync & Share Checklist File sync and share has changed the way people work and collaborate in today's tech-savvy world. Gone are the email roadblocks, clunky FTP...
- Live Webcast LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy... All Security White Papers | Webcasts