Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Apple

February 2nd, 2012, 09:32 GMT · By

Apple Strengthens Snow Leopard Security with Update 2012-001

SHARE:

Adjust text size:


Security Update 2012-001 (Snow Leopard) listing
Enlarge picture
A security update, targeting users of Mac OS X 10.6 Snow Leopard, has been released by Apple alongside OS X 10.7.3, the newest version of OS X Lion.

Over 50 vulnerabilities are listed on Apple’s Support site, some of which are pretty serious. For example in areas like SquirrelMail and Webmail, security researchers have found (and fixed) cross-site scripting vulnerabilities.

Per Apple’s support document, “SquirrelMail is updated to version 1.4.22 to address several vulnerabilities, the most serious of which is a cross-site scripting issue. This issue does not affect OS X Lion systems.”

The company advises users to visit the SquirrelMail web site for further information.

Webmail, on the other hand, suffers from a cross-scripting (XSS) issue that’s present only on OS X Lion, and does not affect Snow Leopard. According to Apple, “viewing a maliciously crafted e-mail message may lead to the disclosure of message content.”

“A cross-site scripting vulnerability existed in the handling of mail messages,” reads the description. “This issue is addressed by updating Roundcube Webmail to version 0.6. This issue does not affect systems prior to OS X Lion,” Apple clarifies.

A total of six vulnerabilities have been discovered in QuickTime, all of which could lead to an unexpected application termination or arbitrary code execution. Apple fixed them all in Security Update 2012-001 and OS X Lion 10.7.3.

Another important fix targets Data Security, with Apple noting that “An attacker with a privileged network position may intercept user credentials or other sensitive information.”

Another one is for the Address Book application. Bernard Desruisseaux of Oracle Corporation discovered that “A downgrade issue caused Address Book to attempt an unencrypted connection if an encrypted connection failed.”

He thus concluded that “An attacker in a privileged network position could abuse this behavior to intercept CardDAV data. This issue is addressed by not downgrading to an unencrypted connection without user approval.”

There’s a Client version and a Server version of the Security Update 2012-001 for Snow Leopard. You can download any one of them via the links below. Alternately, use the Software Update mechanism on your Mac to download and install the updates.

Download Security Update 2012-001 Server (Snow Leopard)

Download Security Update 2012-001 Client (Snow Leopard)

TELL US WHAT YOU THINK:

1,037 hits · 2 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Apple Updates Lion Server Apps with Server Admin Tools 10.7.3

Download Apple Remote Desktop 3.5.2 Client

Lion Server Updated with Tons of Enhancements

Download OS X Lion 10.7.3 Final with Safari 5.1.3

Some Versions of OS X Lion Don’t Support FCP X 10.0.3

READER COMMENTS:


Comment #1 by: Nessa on 02 Feb 2012, 18:02 UTC reply to this comment

Don't download this yet! It kills a lot of Rosetta programs and Microsoft Office... Be careful. It's left me unable to function in some of my work duties.


Comment #2 by: Paul Johnson on 03 Feb 2012, 06:01 UTC reply to this comment

DO NOT INSTALL Security Update 2012-001. It breaks PPC applications that require Rosetta to run.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM