news, events, reviews

Apple has released Security Update 2007-009 for both Mac OS X Leopard and Tiger ( Intel , PowerPC ). The company recommends the update for all users. Among the included security enhancements are the closures of several bugs where visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. For instance, a Tiger-specific format string vulnerability exists in Address Book’s URL handler.

By enticing a user to visit a maliciously crafted website, a remote attacker may cause an unexpected application termination or arbitrary code execution. This update addresses the issue through improved handling of format strings. Another Tiger-specific issue, the potential for memory corruption in the handling of images with an embedded ColorSync profile is exploited by enticing a user to open a maliciously crafted image.

This update addresses the issue by performing additional validation of images.

Leave a comment

You must be logged in to post a comment.

 

About Us

Community of those who are fond of Apple's ideas, design and all that incredible things they do. If you like PC's - that's your choice. We proudly consider Apple, with it's iPhone, iPod & sure - Apple Mac Air - is the best!