Apple Security Update 2008-005 Fixes DNS Issue
July 31st, 2008 at 3:00 PM - News by Jeff Gamet
Apple rolled out a late day security update on Thursday that addressed potential DNS-related flaws in Mac OS X Leopard and Tiger. Security Update 2008-005 prevents malicious attackers from forging Web sites -- a trick that could potentially be used for phishing attacks where hackers trick Web surfers into giving up personal information like passwords and bank account data.
The security update fixed flaws that could allow an attacker to use the Open Scripting Architecture to run commands with elevated privileges. It also addressed problems where maliciously crafted Web sites could use CoreGraphics to crash applications or run arbitrary code, maliciously crafted messages could use Data Detectors to crash applications, emac could be used to gain System Privileges after Disk Utilityis Repair Permissions tool has been run, and OpenLDAP and OpenSSL could be used to crash applications or run arbitrary code.
PHP was updated to version 5.2.6 to block several potential security issued that could lead to crashed applications or arbitrary code execution.
A flaw in QuickLook was patched that could lead to crashed apps or arbitrary code execution, and rsync was updated to prevent remote attackers from accessing or overwriting the module root.
Security Update 2008-005 requires Mac OS X 10.4.11 or 10.5.4, or Mac OS X Server 10.4.11 or 10.5.4. It is available via Appleis Software Update application, or as a downloadable installer at the Apple Support Web site.
Recent Headlines - Updated March 11th
- Thu, 12:16 PM
- Product News - SiteGrinder 3 Offers 300+ New Features for Photoshop Web Dev
- 11:16 AM
- TMO Appearances - Ted Landau Discusses Tethering, Google Voice on MacNotables
- 10:45 AM
- News - Apple Tops Consumer Reports Customer Service Survey
- 10:19 AM
- Hot Forum Topic - Reader Discussion: Ramping Up for iPad Pre-orders
- 9:16 AM
- TMO Appearances - TMO’s Jeff Gamet Shares Cool iPhone Apps at CoMUG
- 8:44 AM
- News - Court to EMI: Don’t Break Up Floyd
- 8:16 AM
- Product News - Metron 2 Adds Rhythm Patterns, More
- Wed, 4:54 PM
- iPad - Amazon, Google, Dell to Take on iPad With Dell Streak Tablet
- 4:04 PM
- Games - Mac Version of Fallen Earth MMO Enters Open Beta
- 3:56 PM
- Ted Landau's User Friendly View - iPhone Internet Tethering and the iPad
- 3:31 PM
- iPhone - Stanford Survey Finds iPhone Addicting
- 3:01 PM
- News - Bing Takes Search Traffic Share at Yahoo’s Expense
The Mac Observer Reader Specials
- TypeStyler For Mac OS X is Now Shipping! Download The Free Fully Functional 60 Day Tryout at www.typestyler.com
Mac Memory and Hard Drives: MacBook Pro Memory 8GB kits $349.99! iMac Memory 4GB DDR Kits for $109.99! Mac Pro Memory 4GB Kits for $135.99! Mac Hard Drives 1.5TB Seagate SATA II for $147.99! Click Here!
- CarMD Handheld Device & Mac/PC Software System saves you time and money on car maintenance and repair. Buy at www.CarMD.com! Save $10 with code TMO2.
If you're using a Mac, then you've gotta check out Full Tilt Poker for Mac. This Full Tilt Poker bonus code does the unthinkable, it actually rewards!For the latest Apple products use Ciao, a price comparison website, to find laptops like MacBook Air. Then find the best prices on MP3 players and use our comparison tool to evaluate mobile phones like the Apple iPhone.


Refurbished MacBook Air 1.6GHz Intel Core 2 Duo $1099.00 Delivered
