Apple Plugs iChat, Safari Security Holes

By Nate Mook | Published March 1, 2006, 7:05 PM

In its first standalone security update for 2006, Apple on Wednesday plugged 17 flaws affecting both Mac OS X 10.3 and 10.4. The fixes come after two potential vulnerabilities -- one in iChat and another in Safari -- were heavily publicized and brought warnings from security experts that Macs are not immune from malware.

The first claims of a Mac "virus" surfaced mid-February with the discovery of Leap.A, which is distributed as an archive. Once Leap.A is activated, when any iChat user changes his or her status, the worm initiates a file transfer for the latestpics.tgz archive.

The file transfer takes place in the background and is hidden from the user. In addition, the malware replaces all applications that have been used in the last month with itself, saving the original executable as a resource fork with the same filename.

Shortly after reports of Leap.A hit the Web, Apple downplayed the threat and said it was not a virus. As part of Wednesday's security update, the company said, "iChat now uses Download Validation to warn of unknown or unsafe file types during file transfers."

A second flaw in Mac OS X was publicized last week, pertaining to the way Safari executes what it believes are "safe" files after downloading. A file could actually be a malicious script, which is executed using the operating system's Terminal application, rather than the movie or picture is masquerades as.

In Wednesday's advisory, Apple says, "This update addresses the issue by performing additional download validation so that the user is warned (in Mac OS X v10.4.5) or the download is not automatically opened (in Mac OS X v10.3.9)."

The 15 other fixes include three other flaws in Safari, additional download validation in Apple Mail, improvements to FileVault, and fixes in Unix applications that are bundled with Mac OS X, including PHP, Rsync and Perl. Apple has also patched a cross-site scripting vulnerability in its RSS feed handling.

Mac OS X users can download the update now via Software Update.

Comments

>> Are Apple products more prone to holes and worms than any other OS? Afterall, it is an Apple. Right?

Haha! Funny! :D

Really though...lets not get into this debate. OSX gets patched before malicious people take advantage of its flaws. Windows doesn't. Whether there's more malicious hackers for x86, or there's more people pissed at MS, it doesn't change the fact that at the current time Apple is managing to keep OSX patched and secure in a very timely fashion.

Someone cracked their x86 OSX to run on an AMD system in record time though, so...

Score: 0

|

I agree. Apple products are absolutely not more prone to holes and worms, and won't be unless Apple gains some serious significant market share, which won't happen any time in the immediate future. Also, there's no difference in the naming something a "patch" or an "update", if they essentially are the same thing. As stated by Kramy, we get preventitive updates, while Microsoft patches their problems on Tuesdays. Seems a little silly to me that people have to wait for a certain date to update their systems. I can recall not too long ago this being a major issue..... :::cough::: WMF exploit :::cough:::

By the time Microsoft patched that issue, there were thousands of variants floating around the internet infecting unsuspecting users' machines. By the time Tuesday rolled around for them, it was too late.

As far as Apple's security threat, it's hard for anyone with intelligence to label Leap.A as a "virus", but Apple has responded in a timely fashion, and not blown it off as a non existant threat, as Microsoft has done so many countless times in the past.

Score: 0

|

These must be bad holes for apple to not "market" security patches as a point release. We all know that all OSs have security releases, but Apple does a better job of spinning these as updates and not patches.

I just thought of something. Are Apple products more prone to holes and worms than any other OS? Afterall, it is an Apple. Right?

Score: 0

|

Well done Apple. I'm sure they won't rest on their laurels and will continue to release security fixes in a timely fashion.

Score: 0

|

Silverlight 3 goes live on Microsoft's servers

Microsoft's answer to Adobe's Flash is (unofficially) here, with prospects of higher-speed, higher-resolution video and for the first time, 3D.

Three Android phones on the way from T-Mobile in 2009

T-Mobile's myTouch 3G, launched Wednesday, will be followed by two more Android phones later this year, but neither of them will be HTC's Hero.

Best Buy-brand TVs to get TiVo

A new alliance will place the retailer's own brand alongide the manufacturers, and could also lead to future partnerships on services.

LTE still lacks a voice

The 4G Wireless standard that Verizon hopes to show off before this year is out is still at a loss for (spoken) words.

Data sharing among online advertisers: Is sanity in sight?

Lockdown with Angela Gunn In the middle of a 15-page plea not to get regulated, a spark of smart thinking.

T-Mobile's strategy to combat Apple's iPhone with Android

With a trio of Android phones now in the pipeline for 2009, T-Mobile hopes to break the iPhone's emerging stranglehold.

EC's Reding: Government should act as broker for media downloads

If Internet media services don't step up and build an attractive way for users to start paying for downloads, a commissioner says, government may do the job instead.

Sony TVs get Netflix, still no PS3

Though it's coming in behind LG, Samsung, and Microsoft, Sony will begin to offer Netflix streaming, too.

Google Chrome OS: Too little, too early

Carmi Levy: Wide Angle Zoom Don't start the revolution just yet, says Carmi, who isn't so certain Chrome OS will be the "Windows Killer."

GAO pen test brings the hammer down on federal rent-a-cops

But are the computers to blame for the contract-guard fiasco at FPS?

What's Next: Chrome OS will have at least some friends in high places

Also: South Korea takes another round of DDoS abuse, and Neelie Kroes and Steve Ballmer may shake hands before she exits stage left.

Report: Evidence of further creativity with Windows 7 upgrade prices

A ZDNet blogger did some serious digging for clues as to a reported price break on multiple Windows 7 Home Premium licenses, and may have found it.