Site icon Secplicity – Security Simplified

Huge OS X Update Closes 134 Security Holes

Summary:

Exposure:

Today, Apple released a security update to fix vulnerabilities in all current versions of OS X. The update fixes 134 (number based on CVE-IDs) security issues in 34 components that ship as part of OS X or OS X Server, including Quicktime, ImageIO, and Apache. Some of the fixed vulnerabilities include:

Apple’s alert also describes many other code execution vulnerabilities, as well as some Denial of Service (DoS) flaws, cross-site scripting (XSS) vulnerabilities, information disclosure flaws, and other security issues. Components patched by this security update include:

AFP Server Apache mod_perl
Apache AppKit
ATS CFNetwork
CoreGraphics CoreText
CUPS Directory Service
diskdev_cmds Disk Images
Flash Player plugin gzip
Image Capture ImageIO
Image RAW Kernel
MySQL neon
Networking OpenLDAP
OpenSSL Password Server
PHP Printing
python QuickLook
QuickTime Safari RSS
Time Machine Wiki Server
X11 xar

Please refer to Apple’s OS X 10.5.x and 10.6.x alert for more details.

Solution Path:

Apple has released OS X Security Update 2010-007 and OS X 10.6.5 to fix these security issues. OS X administrators should download, test, and deploy the corresponding update as soon as they can.

Note: If you have trouble figuring out which of these patches corresponds to your version of OS X, we recommend that you let OS X’s Software Update utility pick the correct updates for you automatically.

For All Users:

These flaws enable many diverse exploitation methods. Some of the exploits are local, meaning that your perimeter firewall never encounters the attack (unless you use firewalls internally between departments). Installing these updates, therefore, is the most secure course of action.

Status:

Apple has released updates to fix these flaws.

References:

This alert was researched and written by Corey Nachreiner, CISSP.

 

Exit mobile version