albtechportal

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 5 June 2013

Apple Fixes Serious Flaws You Didn't Know About in OS X

Posted on 14:15 by Unknown
Apple fixed a number of serious vulnerabilities in OS X, the Safari Web browser, and a handful of third-party packages as part of a substantial update. The patches are available on Software Update and users should make sure the fixes are applied immediately.
The updates, which affect all supported versions of OS X–Mountain Lion (10.8), Lion (10.7) and Snow Leopard (10.6)–and closed several remote code execution flaws in the operating system and Safari, Apple said in its advisory posted yesterday. The patches also addressed issues in QuickTimes and the OS X implementation of OpenSSL and Ruby. The Ruby bugs are currently being exploited in the wild.
Multiple vulnerabilities have recently been identified in Ruby on Rails, the most serious of which can result in attackers remotely executing code on systems running Rails applications. Apple addressed eight distinct vulnerabilities by updating Ruby on Rails in OS X to version 2.3.18. This issue will likely impact OS X Lion or OS X Mountain Lion systems that were upgraded from Mac OS X 10.6.8 or earlier, Apple said.
OS X FixesApple fixed several remote code execution bugs in the operating system. Attackers could exploit one such flaw in the CoreAnimation component, where all the user has to do is browse to a maliciously crafted URL in order to get compromised. Another bug in he Playback component could be exploited with a maliciously crafted movie file, Apple said. There are four different patches for QuickTime fixing remote code execution flaws which could be exploited by maliciously crafted MP3, FPX, QTIF, and other movie files.
Another serious remote code execution bug was in the Directory Service component, but it affected only users with Snow Leopard systems who have enabled the service. Directory Service tracks all the user and group authentication information using various platforms, including Active Directory, LDAP, AppleTalk, and SMB file sharing. Apple replaced Diectory Service with Open Directory in Lion and Mountaion Lion.
Attackers could exploit the flaw by sending a maliciously crafted message over the network to to cause the directory server to crash or remotely execute code, Apple said.
OpenSSL, Safari IssuesApple fixed 13 issues in OpenSSL, one of which would allow attackers to launch the CRIME attack, where an attacker could decrypt SSL-protected sessions. The compression attack on TLS 1.0 was developed by security researchers Thai Duong and Juliano Rizzo.
The new Safari, version 6.0.5, fixed 23 distinct remote code execution vulnerabilities and three cross-site scripting flaws. The issues were all related to the WebKit engine that powers the browser.
"Multiple memory corruption issues existed in WebKit," Apple said in its advisory.
These issues expose Mac users to infection-by-browsing attacks, and the attackers would be able to execute code outside the browser and directly on the system without needing user authorization. Cross-site scripting bugs also allow attackers to create malicious sites containing elements from legitimate pages to trick users in to thinking these spoofed sites are trustworthy.
Get That UpdateUsers who use Apple's Software Update get the correct update automatically. Users who decide to do it manually will need to grab the OS X 10.8.4 update (which includes Safari 6.0.5) for Mountaion Lion and Security Update 2013-002 (which doesn't include the Safari update) for Snow Leopard and Lion systems. Please note that Snow Leopard doesn't get the new Safari version as it is still on Safari 5.

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Mac, News | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Review: Seagate 600 480GB SSD
    Seagate Joins the Fray It’s been quite an interesting turn of events over the past couple years in the storage industry. Whereas practical...
  • Top 10 Ways to Customize Your Desktop
    1 Expand You spend a lot of waking hours at your computer, so why not make it a little prettier (and more productive)? Here are 10 ways to...
  • CCBoot - LAN Boot Software for Windows
    LAN Boot Solution Background LAN boot is a technology based on IP (Internet Protocol), UDP (User Datagram Protocol), DHCP (Dynamic ...
  • ‘Strata’ for iOS and Android game review
    There are games that are fun. There are games that look great. And then there are games that do both. Strata is one such game that h...
  • Adobe Photoshop CS6 Extended 13.0 & Plugins + Textures
    Adobe Photoshop CS6 Extended 13.0 & Plugins + Textures | 3.5 GB Adobe Photoshop CS6 Extended software delivers even more imaging magi...
  • Intel NUC DC53427RKE / HYE Review
    Manufacturer: Intel UK Price (as reviewed): £308.32 (inc VAT) US Price (as reviewed): $539.99 (ex TAX) Preferred Partner Price: £308.32...
  • ASUS R9 270X DirectCU II TOP 2 GB
    AMD's new Radeon R9 270X draws its lineage more from the Radeon HD 7800 series than any other. The R9 270X is, for all intents and purp...
  • Corsair Raptor M40 Review
    Manufacturer: Corsair UK price (as reviewed): £44.99 (inc VAT) US price (as reviewed): $59.99 (ex Tax) Along with the Raptor M30, Corsai...
  • Call of Duty: Ghosts Review
    Developer: Infinity Ward Publisher: Activision Platforms: PC, X360, PS3, PS4, Xbox One Price: £39.99 Reviewing a Call of Duty game is a ...
  • How to remotely install apps on your smartphone
    You can download and install apps to your iPhone and Android phone without being anywhere near it. That sorcery is this? It isn't sorce...

Categories

  • Android
  • Apple
  • Audio
  • Blogger
  • C/C++
  • Cabling
  • Cameras
  • Cases
  • CISCO
  • Cooling
  • CPU
  • Desktop
  • DNS
  • Ebook
  • Fiber Optic
  • Gadgets
  • Game
  • Google
  • Graphic Card
  • Hardware
  • HDD
  • HTC
  • HTMLCSS
  • Hyper-V
  • Intel
  • iOS
  • iPad
  • Iphone
  • IT
  • jQuery
  • Laptop
  • Linux
  • Mac
  • MacTut
  • Microsoft
  • Mobile
  • Mouse
  • Networking
  • News
  • Nexus
  • Nokia
  • Nvidia
  • OS
  • PERIPHERALS & COMPONENTS
  • Photoshop
  • Printers
  • Programming
  • Projectors
  • PS4
  • Ram
  • RedHat
  • Review
  • Samsung
  • Scanners
  • Seagate
  • Security
  • Server2008
  • Server2012
  • Servers
  • Smartphone
  • Software
  • Sony
  • Storage
  • Tablets
  • TechNews
  • Template
  • Tutorials
  • TV
  • Ubuntu
  • Voip
  • Webdesign
  • Webiste
  • WebServer
  • Win7
  • Win8
  • Windows Phone
  • Wordpress
  • Workstation
  • XBOX

Blog Archive

  • ▼  2013 (495)
    • ►  December (35)
    • ►  November (332)
    • ►  October (12)
    • ►  September (27)
    • ►  August (2)
    • ►  July (10)
    • ▼  June (42)
      • Six Predictions for Cloud Collaboration in 2013
      • Understanding VLAN Trunk Protocol (VTP)
      • Creating a Mail Server on Ubuntu (Postfix, Courier...
      • Voice Over Internet Protocol (VoIP)
      • Advantages and disadvantages of computers
      • How to make Ubuntu bootable USB
      • Networking Tutorials
      • Why you need a Firewall
      • Online Banking - Essential Security Measures
      • Secure Your PC All about SpyWare
      • Trojan Detection
      • Installing and Testing Wampserver
      • Web Server Tutorial
      • With IE11, Microsoft gets all touchy-feely
      • How to Allow Users to Subscribe to Categories in W...
      • Install Graphical user interface (GUI) in Ubuntu 1...
      • 10 Hand-Picked Tutorials for Beginning Web Designers
      • The Sideswipe Home Screen
      • Top 10 Computer Tricks Every Geek Should Know
      • iPhone 5 tips and tricks
      • Samsung Galaxy S4 Mini review
      • What Is Network Security?
      • Packet-switching
      • Routers and Switches
      • Mixed Networks
      • Fully Switched Networks
      • The Problem: Traffic & Solution
      • Network Topologies
      • How LAN Switches Work
      • Networking Basics: What You Need To Know
      • Sony Xperia Tablet Z Review: Sony Gets It (Mostly)...
      • iOS 7 and its 10 Best Features Explained
      • Xbox One Pricing and Availability Announced
      • How to print directly from the Android phone
      • Choosing a Gaming CPU at 1440p: Adding in Haswell
      • Samsung Makes Galaxy S 4 Active Official - IP67 an...
      • How to set up VPNing on Windows 8
      • How to Change DNS to google public DNS
      • Photoshop Tips: The Brush Tool
      • HTML5 Slider Tutorial Javascript Function Programming
      • Apple Fixes Serious Flaws You Didn't Know About in...
      • Choosing a Gaming CPU
    • ►  May (35)
Powered by Blogger.

About Me

Unknown
View my complete profile