Security Update 2006-001 available

Apple products and Mac operating systems. Including discussions on Virtual PC for Mac, Parallels Desktop for Mac, all Apple hardware and everything relating to Mac!
(MacCentre701)

Moderator: Mandrake

Security Update 2006-001 available

Postby Antony » Wed 01 Mar, 2006 6:22 pm

Image
Apple released Security Update 2006-001 Mac OS X 10.4.5
About Security Update 2006-001 Mac OS X 10.4.5 (PPC)
Security Update 2006-001 is recommended for all users and improves the security of the following components.

apache_mod_php
automount
Bom
Directory Services
iChat
IPSec
LaunchServices
LibSystem
loginwindow
OpenSSH
rsync
Safari
Syndication


For detailed information on this Update, please visit this website: http://docs.info.apple.com/article.html?artnum=61798


:dl: Security Update 2006-001 Mac OS X 10.4.5 (PPC) (12.5 MB)
:dl: Security Update 2006-001 Mac OS X 10.4.5 Client (Intel) (22.5 MB)
UserAgent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/417.9 (KHTML, like Gecko) Safari/417.8
Last edited by Antony on Wed 01 Mar, 2006 7:03 pm, edited 2 times in total.
User avatar
Antony
diamond member
diamond member
 
Posts: 14510
Joined: Tue 18 Jun, 2002 11:36 pm
Location: Sydney, Australia

Postby J-M » Wed 01 Mar, 2006 6:32 pm

Serious flaw in Safari browser (see http://sillydog.org/forum/viewtopic.php?t=10910 for details) has been reportedly fixed as well:

Report from SANS Internet Storm Center
http://isc.sans.org/diary.php?storyid=1160

ISC says iChat and Mail are also immune now. Time to patch:
http://www.apple.com/support/downloads/
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.0; fi-FI; rv:1.7.12) Gecko/20050919 Firefox/1.0.7
User avatar
J-M
diamond member
diamond member
 
Posts: 815
Joined: Sun 25 Jul, 2004 9:16 am
Location: Helsinki, Finland

Postby Antony » Wed 01 Mar, 2006 6:34 pm

Thanks for confirming Safari and iChat, Mail security related issues, J-M.
UserAgent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/417.9 (KHTML, like Gecko) Safari/417.8
User avatar
Antony
diamond member
diamond member
 
Posts: 14510
Joined: Tue 18 Jun, 2002 11:36 pm
Location: Sydney, Australia

Postby Antony » Wed 01 Mar, 2006 7:35 pm

Security Update 2006-001 for Mac OS X 10.3.9 Panther users is also available.

Security Update 2006-001(10.3.9 Client)

About Security Update 2006-001 (Panther Client)
Security Update 2006-001 is recommended for all users and improves the security of the following components.

apache_mod_php
automount
Bom
Directory Services
IPSec
LibSystem
loginwindow
perl
Safari

Additionally, Security Update 2005-008 and Security Update 2005-009 have been incorporated into this security update.

For detailed information on this Update, please visit this website: http://docs.info.apple.com/article.html?artnum=61798


:dl: Security Update 2006-001(10.3.9 Client) (25.3 MB)
UserAgent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/417.9 (KHTML, like Gecko) Safari/417.8
User avatar
Antony
diamond member
diamond member
 
Posts: 14510
Joined: Tue 18 Jun, 2002 11:36 pm
Location: Sydney, Australia

Postby J-M » Thu 02 Mar, 2006 8:52 am

There is an exploit code for "passwd" program temporary file creation vulnerability published too.

Details at
http://www.frsirt.com/english/advisories/2006/0791

-> see The fourth issue...

Code was published at
http://www.frsirt.com/exploits/20060301 ... swd.pl.php

late on Wednesday.
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.0; fi-FI; rv:1.7.12) Gecko/20050919 Firefox/1.0.7
User avatar
J-M
diamond member
diamond member
 
Posts: 815
Joined: Sun 25 Jul, 2004 9:16 am
Location: Helsinki, Finland

Postby J-M » Thu 02 Mar, 2006 8:56 am

More information about these security issues has been published at Secunia Advisory SA19064; see
http://secunia.com/advisories/19064/

FrSIRT has its advisory FrSIRT/ADV-2006-0791 located at
http://www.frsirt.com/english/advisories/2006/0791

Both of these have highest severity level in use; Secunia says Extremely Critical (5/5) and FrSIRT Critical Risk (4/4).
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.0; fi-FI; rv:1.7.12) Gecko/20050919 Firefox/1.0.7
User avatar
J-M
diamond member
diamond member
 
Posts: 815
Joined: Sun 25 Jul, 2004 9:16 am
Location: Helsinki, Finland

Postby Pu7o » Fri 03 Mar, 2006 4:17 am

The Panther version of the security update seems to bump the Safari useragent to v312.6.
UserAgent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/312.8 (KHTML, like Gecko) Safari/312.6
User avatar
Pu7o
Macfox
Macfox
 
Posts: 2014
Joined: Thu 06 Jan, 2005 12:03 pm
Location: Portugal


Return to Mac OS and Apple

Who is online

Registered users: Google [Bot]

cron