albtechportal

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 5 June 2013

Apple Fixes Serious Flaws You Didn't Know About in OS X

Posted on 14:15 by Unknown
Apple fixed a number of serious vulnerabilities in OS X, the Safari Web browser, and a handful of third-party packages as part of a substantial update. The patches are available on Software Update and users should make sure the fixes are applied immediately.
The updates, which affect all supported versions of OS X–Mountain Lion (10.8), Lion (10.7) and Snow Leopard (10.6)–and closed several remote code execution flaws in the operating system and Safari, Apple said in its advisory posted yesterday. The patches also addressed issues in QuickTimes and the OS X implementation of OpenSSL and Ruby. The Ruby bugs are currently being exploited in the wild.
Multiple vulnerabilities have recently been identified in Ruby on Rails, the most serious of which can result in attackers remotely executing code on systems running Rails applications. Apple addressed eight distinct vulnerabilities by updating Ruby on Rails in OS X to version 2.3.18. This issue will likely impact OS X Lion or OS X Mountain Lion systems that were upgraded from Mac OS X 10.6.8 or earlier, Apple said.
OS X FixesApple fixed several remote code execution bugs in the operating system. Attackers could exploit one such flaw in the CoreAnimation component, where all the user has to do is browse to a maliciously crafted URL in order to get compromised. Another bug in he Playback component could be exploited with a maliciously crafted movie file, Apple said. There are four different patches for QuickTime fixing remote code execution flaws which could be exploited by maliciously crafted MP3, FPX, QTIF, and other movie files.
Another serious remote code execution bug was in the Directory Service component, but it affected only users with Snow Leopard systems who have enabled the service. Directory Service tracks all the user and group authentication information using various platforms, including Active Directory, LDAP, AppleTalk, and SMB file sharing. Apple replaced Diectory Service with Open Directory in Lion and Mountaion Lion.
Attackers could exploit the flaw by sending a maliciously crafted message over the network to to cause the directory server to crash or remotely execute code, Apple said.
OpenSSL, Safari IssuesApple fixed 13 issues in OpenSSL, one of which would allow attackers to launch the CRIME attack, where an attacker could decrypt SSL-protected sessions. The compression attack on TLS 1.0 was developed by security researchers Thai Duong and Juliano Rizzo.
The new Safari, version 6.0.5, fixed 23 distinct remote code execution vulnerabilities and three cross-site scripting flaws. The issues were all related to the WebKit engine that powers the browser.
"Multiple memory corruption issues existed in WebKit," Apple said in its advisory.
These issues expose Mac users to infection-by-browsing attacks, and the attackers would be able to execute code outside the browser and directly on the system without needing user authorization. Cross-site scripting bugs also allow attackers to create malicious sites containing elements from legitimate pages to trick users in to thinking these spoofed sites are trustworthy.
Get That UpdateUsers who use Apple's Software Update get the correct update automatically. Users who decide to do it manually will need to grab the OS X 10.8.4 update (which includes Safari 6.0.5) for Mountaion Lion and Security Update 2013-002 (which doesn't include the Safari update) for Snow Leopard and Lion systems. Please note that Snow Leopard doesn't get the new Safari version as it is still on Safari 5.

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Mac, News | No comments
Newer Post Older Post Home
View mobile version

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • ‘Strata’ for iOS and Android game review
    There are games that are fun. There are games that look great. And then there are games that do both. Strata is one such game that h...
  • Call of Duty: Ghosts Review
    Developer: Infinity Ward Publisher: Activision Platforms: PC, X360, PS3, PS4, Xbox One Price: £39.99 Reviewing a Call of Duty game is a ...
  • Review: Seagate 600 480GB SSD
    Seagate Joins the Fray It’s been quite an interesting turn of events over the past couple years in the storage industry. Whereas practical...
  • CCBoot - LAN Boot Software for Windows
    LAN Boot Solution Background LAN boot is a technology based on IP (Internet Protocol), UDP (User Datagram Protocol), DHCP (Dynamic ...
  • Adobe Photoshop CS6 Extended 13.0 & Plugins + Textures
    Adobe Photoshop CS6 Extended 13.0 & Plugins + Textures | 3.5 GB Adobe Photoshop CS6 Extended software delivers even more imaging magi...
  • iBuypower Chimera 4SE FX Ultimate: AMD Gaming PC
    iBuypower is offering an AMD-based system in its Chimera 4SE line, which is designed to give users serious gaming performance without a wa...
  • Buying Guide: Find the best headphones
    If you’re looking to get more audio enjoyment from your smartphone, tablet, media player, or computer, new headphones will do wonders. And ...
  • The Last Days of the DSLR
    The DLSR is everywhere. You see it around the necks of tourists, against the faces of pro photographers. Since Canon introduced the Digita...
  • Xbox One vs. PS4: How They Stack Up Today
    Two new gaming consoles. Both very powerful. Both very ambitious. Both about to meet head to head... and do battle for your time, money an...
  • How To Splice Fiber Optic Cable - Mechanical Splice
    Instructions for splicing fiber optic cable with the AFL CS004162 mechanical splice kit. Watch quick overview video at bottom of post. 1.0 ...

Categories

  • Android
  • Apple
  • Audio
  • Blogger
  • C/C++
  • Cabling
  • Cameras
  • Cases
  • CISCO
  • Cooling
  • CPU
  • Desktop
  • DNS
  • Ebook
  • Fiber Optic
  • Gadgets
  • Game
  • Google
  • Graphic Card
  • Hardware
  • HDD
  • HTC
  • HTMLCSS
  • Hyper-V
  • Intel
  • iOS
  • iPad
  • Iphone
  • IT
  • jQuery
  • Laptop
  • Linux
  • Mac
  • MacTut
  • Microsoft
  • Mobile
  • Mouse
  • Networking
  • News
  • Nexus
  • Nokia
  • Nvidia
  • OS
  • PERIPHERALS & COMPONENTS
  • Photoshop
  • Printers
  • Programming
  • Projectors
  • PS4
  • Ram
  • RedHat
  • Review
  • Samsung
  • Scanners
  • Seagate
  • Security
  • Server2008
  • Server2012
  • Servers
  • Smartphone
  • Software
  • Sony
  • Storage
  • Tablets
  • TechNews
  • Template
  • Tutorials
  • TV
  • Ubuntu
  • Voip
  • Webdesign
  • Webiste
  • WebServer
  • Win7
  • Win8
  • Windows Phone
  • Wordpress
  • Workstation
  • XBOX

Blog Archive

  • ▼  2013 (495)
    • ►  December (35)
    • ►  November (332)
    • ►  October (12)
    • ►  September (27)
    • ►  August (2)
    • ►  July (10)
    • ▼  June (42)
      • Six Predictions for Cloud Collaboration in 2013
      • Understanding VLAN Trunk Protocol (VTP)
      • Creating a Mail Server on Ubuntu (Postfix, Courier...
      • Voice Over Internet Protocol (VoIP)
      • Advantages and disadvantages of computers
      • How to make Ubuntu bootable USB
      • Networking Tutorials
      • Why you need a Firewall
      • Online Banking - Essential Security Measures
      • Secure Your PC All about SpyWare
      • Trojan Detection
      • Installing and Testing Wampserver
      • Web Server Tutorial
      • With IE11, Microsoft gets all touchy-feely
      • How to Allow Users to Subscribe to Categories in W...
      • Install Graphical user interface (GUI) in Ubuntu 1...
      • 10 Hand-Picked Tutorials for Beginning Web Designers
      • The Sideswipe Home Screen
      • Top 10 Computer Tricks Every Geek Should Know
      • iPhone 5 tips and tricks
      • Samsung Galaxy S4 Mini review
      • What Is Network Security?
      • Packet-switching
      • Routers and Switches
      • Mixed Networks
      • Fully Switched Networks
      • The Problem: Traffic & Solution
      • Network Topologies
      • How LAN Switches Work
      • Networking Basics: What You Need To Know
      • Sony Xperia Tablet Z Review: Sony Gets It (Mostly)...
      • iOS 7 and its 10 Best Features Explained
      • Xbox One Pricing and Availability Announced
      • How to print directly from the Android phone
      • Choosing a Gaming CPU at 1440p: Adding in Haswell
      • Samsung Makes Galaxy S 4 Active Official - IP67 an...
      • How to set up VPNing on Windows 8
      • How to Change DNS to google public DNS
      • Photoshop Tips: The Brush Tool
      • HTML5 Slider Tutorial Javascript Function Programming
      • Apple Fixes Serious Flaws You Didn't Know About in...
      • Choosing a Gaming CPU
    • ►  May (35)
Powered by Blogger.

About Me

Unknown
View my complete profile