NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Apple / Mac

Mac


DNS Flaw Fixed in Security Update 2008-006

Sixth standalone security package for OS X Leopard users available

By Filip Truta, Apple News Editor

16th of September 2008, 08:36 GMT

Adjust text size:


Installer package
Enlarge picture
Although the Mac OS X 10.5.5 Leopard software update patches all the security holes acknowledged lately, Apple has also released the package containing only the security fixes found in the major update. Users can download the installer package suitable for their hardware and OS for free.

Apple notes that the sixth Security Update (2008-006) released
for the Client and Server versions (Intel, PPC and Universal) of its OS is recommended for all users, as it improves the security of their operating system. As always, previous security updates have been incorporated into this update, meaning that if you've skipped Security Update 2008-005 (or earlier versions), you can safely download and install this package, and not miss out on any of the patches.

On its Support section, Apple details the security content of Mac OS X v10.5.5 and Security Update 2008-006, pointing out to the affected elements of OS X Leopard. Tackling 25 bugs in total, the most noteworthy fix is related to a critical Internet security flaw that Apple failed to patch earlier this year.

Apple has fixed a flaw in the Mac OS X Libresolv DNS software, discovered by security researcher Dan Kaminsky and that could have allowed attackers to trick victims into visiting malicious websites using what's known as a “cache poisoning attack.” According to Andrew Storms, director of security operations with security vendor nCircle, although Internet Systems Consortium had patched Libresolv by the time Apple released its last security update, the bug fix was not included in the package. Tests have already confirmed that attempts of tricking users into visiting malicious sites are now more difficult to pull off, thanks to the address port randomization OS X now requires.

More common OS X components like the Finder and Time Machine, but also open-source components including Ruby ClamAV and OpenSSH, have also been patched in the latest security update from Apple.

A full breakdown of all the areas touched by the Security Update 2008-006 is available on Apple's Support section, here. You may download and install the free security update to Leopard using this here link. Installing Mac OS X 10.5.5 is not required, hence the purpose of this installer package – get the latest security fixes, leave the Leopard enhancements for the brave.

Security Update 2008-006 (PPC, Intel)
Security Update Server 2008-006 (Universal, PPC)

TAGS:

Security Update 2008-006 | Security Update | Software Update | 10.5.5 | Mac OS X
Read by 706 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
NOT RATED 0 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Mac OS X / Server 10.5.5 Combo Updates – Download Here

Apple Releases Mac OS X Server 10.5.5

Mac OS X 10.5.5 Available

HP Printer Driver Update 1.1.1 Available

Apple Re-Releases iTunes 8 for Windows

iPhone 2.1 Packs More than Apple Said

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM