Apple Fixes 13 Bugs in Major OS X Patch Release
Apple released a patch Tuesday that fixes more than a dozen bugs, including a critical remote code-execution flaw in Apple Type Services. The patch release also includes a fix for a flaw in CFNetwork that enabled an attacker to intercept user credentials and other sensitive data silently on a network.
The Apple patch release plugs a total of 13 holes in a variety of OS X components and add-ons, including ClamAV, PHP and Samba. The most serious bug that Apple fixed with this release is the buffer overflow in Apple Type Services which enables an attacker to run arbitrary code on a remote machine.
"A stack buffer overlow exists in Apple Type Services' handling of embedded fonts. Viewing or downloading a document containing a maliciously crafted embedded font may lead to arbitrary code execution. This issue is addressed through improved bounds checking," Apple said in its security bulletin.
Editor's Pick
The OS X update also fixes a vulnerability in Apple's CFNetwork framework which resulted from the framework's support for anonymous SSL/TLS connections.
"This may allow a man-in-the-middle attacker to redirect connections and intercept user credentials or other sensitive information. This issue does not affect the Mail application. This issue is addressed by disabling anonymous TLS/SSL connections," the company said.
Commenting on this Article is closed.
Today's Most Popular
- Researchers Discover Android Mobile Botnet 100k Strong
- Phony Temple Run Game For Android Plays On Android-iOS App Gap
- Adobe's Security Chief Talks About Driving Up The Cost of Exploits
- Hackers Hit Alabama, Mexican Government Websites
- Attackers Using Fake Google Analytics Code to Redirect Users to Black Hole Exploit Kit
Most Commented Stories
-
Attackers Using Fake Google Analytics Code to Redirect Users to Black Hole Exploit Kit (8)
-
Twenty Something Asks Facebook For His File And Gets It - All 1,200 Pages (56)
-
Did Apple, RIM and Nokia Help The Indian Government Spy On The U.S.? (3)
-
Google Begins Security Review Process for Android Apps (2)
-
Costin Raiu on the Timing of the Duqu Attacks (2)
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.



