Monday, May 18, 2009

Apple patch Tuesday

No typo, its MAC’s OS X 10.5.7 turn to apply patches not just performance enhancing but security patches to correct 47 security issues (from PHP and Safari to Adobe and Flash Player updates). Updating various components and applications will require you to restart your MAC...and this is on top of already 90+ vulnerability related to code and 3rd-party applications (Security Update 2008-02 with Tiger/Leopard) already released couple months ago.


Like other critical vulnerabilities, some attributed to potential arbitrary code execution (and is some instance of malware infection)—related to Apache, ClamAV, Flash Player, and Adobe [Security Update 2008-003]…infinite loop enumeration request with AFP Server, heap buffer overflow with CoreText, memory corruption for movie/codec files, and unprivileged local access to the 'Download' folder.

So while Apple has conducted a press release to advocate the patching and forthright position to security and public awareness, they offer no further comments related to prolonged release...
Security Update 2009-003
Security Update 2009-002
Security Update 2009-001
On a concurrent note, Adobe Acrobat is starting to notice flaws (second this year) and other vulnerabilities including the latest zero day related to Javascript, allowing arbitrary code execution or remote attackers DOS (Denial of Service) through annotation and OpenAction entry via JavaScript code.

No comments:

Post a Comment