Apple Plugs iChat, Safari Security Holes

By Nate Mook | Published March 1, 2006, 7:05 PM

In its first standalone security update for 2006, Apple on Wednesday plugged 17 flaws affecting both Mac OS X 10.3 and 10.4. The fixes come after two potential vulnerabilities -- one in iChat and another in Safari -- were heavily publicized and brought warnings from security experts that Macs are not immune from malware.

The first claims of a Mac "virus" surfaced mid-February with the discovery of Leap.A, which is distributed as an archive. Once Leap.A is activated, when any iChat user changes his or her status, the worm initiates a file transfer for the latestpics.tgz archive.

The file transfer takes place in the background and is hidden from the user. In addition, the malware replaces all applications that have been used in the last month with itself, saving the original executable as a resource fork with the same filename.

Shortly after reports of Leap.A hit the Web, Apple downplayed the threat and said it was not a virus. As part of Wednesday's security update, the company said, "iChat now uses Download Validation to warn of unknown or unsafe file types during file transfers."

A second flaw in Mac OS X was publicized last week, pertaining to the way Safari executes what it believes are "safe" files after downloading. A file could actually be a malicious script, which is executed using the operating system's Terminal application, rather than the movie or picture is masquerades as.

In Wednesday's advisory, Apple says, "This update addresses the issue by performing additional download validation so that the user is warned (in Mac OS X v10.4.5) or the download is not automatically opened (in Mac OS X v10.3.9)."

The 15 other fixes include three other flaws in Safari, additional download validation in Apple Mail, improvements to FileVault, and fixes in Unix applications that are bundled with Mac OS X, including PHP, Rsync and Perl. Apple has also patched a cross-site scripting vulnerability in its RSS feed handling.

Mac OS X users can download the update now via Software Update.

Comments

View comments by with a score of at least

>> Are Apple products more prone to holes and worms than any other OS? Afterall, it is an Apple. Right?

Haha! Funny! :D

Really though...lets not get into this debate. OSX gets patched before malicious people take advantage of its flaws. Windows doesn't. Whether there's more malicious hackers for x86, or there's more people pissed at MS, it doesn't change the fact that at the current time Apple is managing to keep OSX patched and secure in a very timely fashion.

Someone cracked their x86 OSX to run on an AMD system in record time though, so...

Score: 0

|

I agree. Apple products are absolutely not more prone to holes and worms, and won't be unless Apple gains some serious significant market share, which won't happen any time in the immediate future. Also, there's no difference in the naming something a "patch" or an "update", if they essentially are the same thing. As stated by Kramy, we get preventitive updates, while Microsoft patches their problems on Tuesdays. Seems a little silly to me that people have to wait for a certain date to update their systems. I can recall not too long ago this being a major issue..... :::cough::: WMF exploit :::cough:::

By the time Microsoft patched that issue, there were thousands of variants floating around the internet infecting unsuspecting users' machines. By the time Tuesday rolled around for them, it was too late.

As far as Apple's security threat, it's hard for anyone with intelligence to label Leap.A as a "virus", but Apple has responded in a timely fashion, and not blown it off as a non existant threat, as Microsoft has done so many countless times in the past.

Score: 0

|

These must be bad holes for apple to not "market" security patches as a point release. We all know that all OSs have security releases, but Apple does a better job of spinning these as updates and not patches.

I just thought of something. Are Apple products more prone to holes and worms than any other OS? Afterall, it is an Apple. Right?

Score: 0

|

Well done Apple. I'm sure they won't rest on their laurels and will continue to release security fixes in a timely fashion.

Score: 0

|

Will Firefox beat IE9 to Direct2D rendering?

Just days after Microsoft executives gave conference attendees a peek at a new rendering technology, a Mozilla contributor revealed he's working on the same thing.

AOL's decision to rebrand as Aol. takes a bad brand and makes it worse

The idea behind the social Web is to crowd source before bringing out something new. But not at AOL, which new logo debuted with a cry of "fail!" across the blogosphere and Twittersphere today.

Microsoft's Bob Muglia and Ray Ozzie on Silverlight vs. standards

Bob Muglia: "We're trying to provide people with an environment that has capabilities that you just simply can't do today in the standards-based world."

Uh-oh, netbooks -- not Windows 7 -- will lift 2009 PC sales

Santa may bring a lump of coal to the Windows PC industry this holiday season. Netbook sales will sap PC margins, while weak Windows 7 PC sales could further drive down average selling prices.

Kindle 2 update adds battery life, native PDF reader

Amazon has pushed out an update to the Kindle 2 e-reader that lengthens battery life and adds a native PDF viewer.

Safari on iPhone gets competition from a $1 browser app

Apple likes to say it gives iPhone users a full browsing experience, but a new competitor tries to incorporate more desktop browser features.

Action Replay maker sues Microsoft for Xbox 360 'predatory technological barriers'

Third-party video game accessory maker Datel has filed an antitrust lawsuit against Microsoft over the Xbox 360's recent Dashboard update.

Where there's smoke: Apple warranty stance raises troubling questions

Carmi Levy | Wide Angle Zoom: Smoking can be dangerous not only for your lungs, it appears, but for your Apple hardware warranty.

Microsoft's .NET Micro Framework is now free and open source

The latest version of Microsoft's .NET Micro framework is now in the hands of the FOSS community.

Google's value proposition for Chrome OS: Should we feel insulted?

For a search engine that has direct access to all the world's online history, it appears to have taught Google nothing about selling a machine.

E-book readers will be in short supply this holiday season

E-readers are hot this year, and a lot of compelling new products have been released, but are there enough electrophoretic displays to go around?