Site icon Secplicity – Security Simplified

Apple OSX: Take Your Leopards In For a Checkup

Summary:

Exposure:

Today, Apple released a security update to fix vulnerabilities in all current versions of OS X. The update fixes around 39 (number based on CVE-IDs) security issues in 22 components that ship as part of OS X or OS X Server, including Airport, Quicktime, and MobileMe. Some of the fixed vulnerabilities include:

Apple’s alert also describes many other code execution vulnerabilities, as well as some Denial of Service (DoS) flaws, privilege escalation vulnerabilities, and information disclosure flaws. Components patched by this security update include:

AirPort App Store
ATS Certificate Trust Policy
ColorSync CoreFoundation
CoreGraphics FTP Server
ImageIO International Components for Unicode
Kernel Libsystem
libxslt MobileMe
MySQL OpenSSL
patch QuickLook
QuickTime Samba
servermgrd subversion

Please refer to Apple’s OS X 10.5.x and 10.6.x alert for more details.

Solution Path:

Apple has released OS X Security Update 2011-004 and OS X 10.6.8 to fix these security issues. OS X administrators should download, test, and deploy the corresponding update as soon as they can.

Note: If you have trouble figuring out which of these patches corresponds to your version of OS X, we recommend that you let OS X’s Software Update utility pick the correct updates for you automatically.

For All Users:

These flaws enable many diverse exploitation methods. Some of the exploits are local, meaning that your perimeter firewall never encounters the attack (unless you use firewalls internally between departments). Installing these updates, therefore, is the most secure course of action.

Status:

Apple has released updates to fix these flaws.

References:

This alert was researched and written by Corey Nachreiner, CISSP. (@SecAdept)

Exit mobile version