NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Apple > Mac

Mac


Apple Recommends Installing Security Update 2009-006

Almost four dozen Mac OS X 10.5 and 10.6 vulnerabilities addressed

By Filip Truta, Apple News Editor

10th of November 2009, 10:45 GMT

Adjust text size:


Mac OS X logo
Enlarge picture
A hefty 143MB download is required on behalf of those who wish only to address the latest security holes found in Mac OS X. Incorporated in the Mac OS X 10.6.2 update as well, Security Update 2009-006 delivers a whopping 44 code corrections on its own.

Among almost four dozen vulnerabilities, discovered with the help of security researchers as well as Apple’s own developers, the Mac maker mentions CoreGraphics and CoreMedia fixes, holes plugged in CUPS and Dictionary, a flaw discovered in Mac OS X that would lead to application termination or arbitrary code execution by downloading a maliciously crafted disk image, and more of the usual stuff.

“Security Update 2009-006 is recommended for all users and improves the security of Mac OS X,” according to the company developing Mac OS X. “Previous security updates have been incorporated into this security update,” Apple informs.

A Spotlight fix included with Security Update 2009-006, for example, is available for Mac OS X v10.5.8 and Mac OS X Server v10.5.8, meaning it does not affect Snow Leopard, the latest version of Apple’s operating system. However, a great deal of Mac owners are still heavily relying on Mac OS X version 10.5 (Leopard), just as most of Microsoft’s loyal customers are still relying on Windows XP. The flaw is described as follows:

“An insecure file operation exists in Spotlight's handling of temporary files,” Apple explains via the Support segment of its web site. “This could allow a local user to overwrite files with the privileges of another user. This update addresses the issue through improved handling of temporary files. This issue does not affect Mac OS X v10.6 systems,” the company states.

Another Leopard-specific fix is contained in this security update, for an integer overflow in QuickLook's handling of Microsoft Office files, which can lead to a buffer overflow, according to Apple. “Downloading a maliciously crafted Microsoft Office file may lead to an unexpected application termination or arbitrary code execution,” the company stresses. “This update addresses the issue through improved bounds checking. This issue does not affect Mac OS X v10.6 systems.”

The 2009-006 security update seems imperative for Mac OS X Leopard and Snow Leopard users alike, as it addresses almost an equal number of weak spots across both OS versions.

Download Apple Security Update 2009-006 (Free)

TAGS:

Security Update | security | 2009-006 | vulnerability | Software Update
Read by 1,065 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
NOT RATED 0 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2010 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Mac OS X v10.6.2 Snow Leopard - The Full Scoop

iPhone Dev Team Posts Ultrasn0w Update for 3.1.x IPSWs

Apple Issues Wireless Keyboard Update 2.0 for Mac OS X

Mac OS X 10.6.2 (Snow Leopard) Available for Download

How to Build and Run Open Source Programs on Your Mac

Shazam Encore Released for iPhone, iPod touch

Download ClamXav Free Virus-Checker for Mac OS X (2.0.4 Beta)

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM