Apple Issues Huge Security Update, Releases OS X 10.6.8
Apple has released a massive set of security updates for Mac OS X and a number of other applications, fixing a total of 39 separate vulnerabilities in programs including QuickTime, MobileMe and others. The company also released OS X 10.6.8.
One of the more serious bugs that Apple fixed with the huge patch release on Thursday is a vulnerability in OS X's certificate trust policy, which governs the ways in which users' systems handle digital certificates. The vulnerability can allow an attacker who already has a foothold on a network to eavesdrop and intercept users' credentials or other sensitive data.
"An error handling issue existed in the Certificate Trust Policy. If an Extended Validation (EV) certificate has no OCSP URL, and CRL checking is enabled, the CRL will not be checked and a revoked certificate may be accepted as valid. This issue is mitigated as most EV certificates specify an OCSP URL," Apple said in its advisory.The certificate trust policy issue was identified and reported by two Google researchers.
Editor's Pick
Apple also released patches for five individual vulnerabilities in QuickTime, which is one of the more widely deployed applications on the Web. It's the default media player for a lot of OS X users, and all of the vulnerabilities that Apple fixed Thursday can be used by an attacker to run arbitrary code on remote machines.
In addition to the QuickTime and certificate bugs, Apple also fixed eight separate flaws in its MySQL implementation in OS X. The application, which ships with OS X Server, had several bugs that could be used for remote code execution. There also were five vulnerabilities in the company's OpenSSL implementation, some of which could be used for remote code execution, as well.
Among the other applications and components that Apple patched are MobileMe, the App Store and many others.
Commenting on this Article is closed.
Today's Most Popular
- Forget 'Brogrammers,' Women Have The Edge In DEFCON Social Engineering Contest
- Dear Jailbreaker, Apple Wants to Have a Word with You
- Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops
- OPINION: Are Anonymous Members Forged in the Crucible of IT Compliance?
- White House Security Czar Howard Schmidt Retiring
Most Commented Stories
-
Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops (5)
-
White House Security Czar Howard Schmidt Retiring (3)
-
Staggering Increase in Android Malware Variants, Trojan Apps (2)
-
Author of LilyJade Facebook Plugin Ignores Facebook Cease-and-Desist (2)
-
New P2P Zeus Variant Targets Popular Sites with Bogus Offers (1)
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.



