Mac OS 10.5.5 packs plethora of security fixes

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

…to DNS cache poisoning and may return forged information.

Apple explained that libresolv provides translation between host names and IP addresses for applications that use its unicast DNS resolution API. A weakness in the DNS protocol may allow remote attackers to perform DNS cache poisoning attacks. Apple credits Dan Kaminsky of IOActive for reporting this vulnerability.

Login Window I
This patch affects users of Mac OS X v10.5 to v10.5.4 and Mac OS X Server v10.5 to v10.5.4.

The update addresses the vulnerability detailed within CVE-2008-3610, in which a user may log in without providing a password.

Apple explained that a race condition exists in Login Window. To trigger this issue, the system must have the guest account enabled or another account with no password. This issue does not affect systems prior to Mac OS X v10.5.

Login Window II
This patch only affects users of Mac OS X v10.4.11 and Mac OS X Server v10.4.11.

The update addresses the vulnerability described in CVE-2008-3611, in which person with access to the login screen may be able to change a user's password.

Apple said that, when a system has been configured to enforce policies on login passwords, users may be required to change their password in the login screen.

If a password change fails, an error message is displayed, but the current password is not cleared and this may not be obvious to the user.

Apple credited Christopher A Grande of Middlesex Community College for reporting this vulnerability.

mDNSResponder
This patch affects users running Mac OS X v10.5 to v10.5.4, and Mac OS X Server v10.5 to v10.5.4.

The update addresses a buffer overflow vulnerability described in CVE-2008-1447, in which mDNSResponder is susceptible to DNS cache poisoning and may return forged information.

Apple credited Dan Kaminsky of IOActive for reporting this vulnerability.

OpenSSH
This patch affects users of Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5 to v10.5.4, and Mac OS X Server v10.5 to v10.5.4.

The update addresses multiple vulnerabilities in OpenSSH described in CVE-2008-1483 and CVE-2008-1657, the most serious of which is local X11 session control.

QuickDraw Manager
This patch only affects users of Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5 to v10.5.4, and Mac OS X Server v10.5 to v10.5.4.

The update addresses the integer overflow vulnerability described in CVE-2008-3614, in which opening a maliciously crafted Pict image may lead to an unexpected application termination or arbitrary code execution.

Ruby
This patch affects users of Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5 to v10.5.4, and Mac OS X Server v10.5 to v10.5.4.

The update addresses a vulnerability described in CVE-2008-2376, in which running a Ruby script that uses untrusted input as the arguments to the Array#fill method may lead to an unexpected application termination or arbitrary code execution.

Apple said there's an integer overflow in rb_ary_fill(), which implements the Ruby Array#fill method.

Search Kit
This patch affects users of Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5 to v10.5.4, Mac OS X Server v10.5 to v10.5.4.

The update addresses a vulnerability described in CVE-2008-3616, in which applications passing untrusted input to the Search Kit API may lead to an unexpected application termination or arbitrary code execution.

Apple explained that an integer overflow issues exist in functions within the Search Kit framework.

System Configuration I
This patch affects users of Mac OS X v10.4.11 and Mac OS X Server v10.4.11.

The update addresses the vulnerability described in CVE-2008-2312, in which a local user may obtain the PPP password.

Apple said Network Preferences stores PPP passwords unencrypted in a world readable file, accessible to any local user.

Apple credited Hernan Ochoa of Core Security Technologies, Tore Halset of pvv.org, and Matt Johnston of the University Computer Club for reporting this vulnerability.

System Preferences I
This patch affects users of Mac OS X v10.5 to v10.5.4, and Mac OS X Server v10.5 to v10.5.4.

The update addresses the vulnerability described in CVE-2008-3617, in which users may be misled into believing their passwords are stronger than they are.

Apple said: "Remote Management and Screen Sharing can be configured to require a password for VNC viewers. The maximum length for VNC viewer passwords is eight characters. The password field can display more than eight characters, implying that the additional characters are used in the password. This update addresses the issue by limiting VNC viewer passwords to eight characters in the user interface."

Apple credits Michal Fresel of hi competence eU for reporting this vulnerability.

System Preferences II
This patch affects users of Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5 to v10.5.3, and Mac OS X Server v10.5 to v10.5.3.

The update addresses the vulnerability described in CVE-2008-3618, in which authenticated users may have unexpected remote access to files and directories.

Time Machine
This patch affects users of Mac OS X v10.5 to v10.5.4, Mac OS X Server v10.5 to v10.5.4.

The update addresses the vulnerability described in CVE-2008-3619, in which backing up a system with Time Machine may lead to the disclosure of sensitive information.

Apple said that, during a Time Machine backup, several log files are saved to the backup drive with read permission allowed to other users and may lead to the disclosure of sensitive information.

VideoConference
This patch affects users of Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5 to v10.5.4, and Mac OS X Server v10.5 to v10.5.4.

The update addresses the vulnerability described in CVE-2008-3621, in which videoconferencing with a malicious user may lead to an unexpected application termination or arbitrary code execution. Apple said a memory-corruption issue exists in the VideoConference framework's handling of H.264 encoded media.

Wiki Server
This patch affects users of Mac OS X v10.5 to v10.5.4, and Mac OS X Server v10.5 to v10.5.4.

The update addresses a divide by zero vulnerability described in CVE-2008-3622, in which a remote attacker may cause persistent JavaScript injection on a Wiki server.

Apple said "the Wiki Server mailing list archive will execute JavaScript code embedded in messages. A remote person may send an email containing JavaScript code to a mailing list hosted on a Wiki server. Viewing the message from the Wiki Server mailing list archive will trigger the execution of the embedded JavaScript code on the system of the person viewing the message."

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

tinycg

Don't forget to check out apps like GoodReader or SlideShark either, they're indispensible for people on the go in presentation situations. Best...

34 minutes ago by tinycg on Four top iPad apps for people on the move
TerryRK

Well it seems there is something a number of us agree on. Why is the Ubuntu Unity launcher so ugly? I thought perhaps it was something to do with...

5 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

15 hours ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

23 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

1 day ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

1 day ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

1 day ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

1 day ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

1 day ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

1 day ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

1 day ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

1 day ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

2 days ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

2 days ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

2 days ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

2 days ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

2 days ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

2 days ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 days ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material