The Mac Observer

Skip navigational links

You're viewing an article in TMO's historic archive vault. Here, we've preserved the comments and how the site looked along with the article. Use this link to view the article on our current site:
Apple Security Update 2008-005 Fixes DNS Issue

Apple Security Update 2008-005 Fixes DNS Issue

by , 7:55 AM EDT, August 1st, 2008

Apple rolled out a late day security update on Thursday that addressed potential DNS-related flaws in Mac OS X Leopard and Tiger. Security Update 2008-005 prevents malicious attackers from forging Web sites -- a trick that could potentially be used for phishing attacks where hackers trick Web surfers into giving up personal information like passwords and bank account data.

The security update fixed flaws that could allow an attacker to use the Open Scripting Architecture to run commands with elevated privileges. It also addressed problems where maliciously crafted Web sites could use CoreGraphics to crash applications or run arbitrary code, maliciously crafted messages could use Data Detectors to crash applications, emac could be used to gain System Privileges after Disk Utility's Repair Permissions tool has been run, and OpenLDAP and OpenSSL could be used to crash applications or run arbitrary code.

PHP was updated to version 5.2.6 to block several potential security issued that could lead to crashed applications or arbitrary code execution.

A flaw in QuickLook was patched that could lead to crashed apps or arbitrary code execution, and rsync was updated to prevent remote attackers from accessing or overwriting the module root.

Security Update 2008-005 requires Mac OS X 10.4.11 or 10.5.4, or Mac OS X Server 10.4.11 or 10.5.4. It is available via Apple's Software Update application, or as a downloadable installer at the Apple Support Web site.

Recent TMO Headlines - Updated February 20th

Sun, 12:16 PM
Don't Fear The Wi-Fi – Mac Geek Gab 645
Sat, 3:47 AM
Apple Answers Tweets in 4 New iPad Pro Ads
Fri, 10:24 PM
WWDC in San Jose Is Closer and Other Apple Insights
Fri, 6:58 PM
AT&T, Sprint, T-Mobile and Verizon Unlimited Data Plan Comparison
Fri, 6:25 PM
Get Free Bitcoins from 11 Faucets That (Still) Pay
Fri, 6:16 PM
iPhone Prototypes Must Be Carried In A Special Case
Fri, 4:59 PM
Apple, Let Us Tune into Those FM Radio Channels
Fri, 4:48 PM
iPhone 8: Goodbye Home Button, Hello Function Area
Fri, 4:38 PM
Amazon is Just Getting Started With Alexa/Echo
Fri, 1:49 PM
iPhone 8 Biometric Sensors, FCC and Smartphone Radio Chips - TMO Daily Observations 2017-02-17
Fri, 12:05 PM
ExoMount Touch Air Vent Car Mount: $16.99
Fri, 9:08 AM
Getting Two-Factor Verification Codes for Your Apple ID
  • __________
  • Buy Stuff, Support TMO!
  • Podcast: Mac Geek Gab
  • Podcast: Apple Weekly Report
  • TMO on Twitter!