Time for a 'Patch Tuesday' just for Apple?

by Scott M. Fulton, III

October 9, 2008, 6:21 PM

In an advisory published by Apple this afternoon, Mac users and admins are being advised of the availability of the seventh major security package this year, which will include some 20 patches for both the System and Mac applications.

The last major Apple security update came on September 15, and the one before was issued on the last day of July. So security updates are getting to be a monthly affair with Apple, just as they've been with Microsoft for quite some time.

But in Apple's case, it's worth noting that security update packages also include patches for third-party Mac and Unix software, provided as a courtesy to their manufacturers or developers. This month, Apple is including what it characterizes as multiple vulnerabilities in the ClamAV open source anti-virus system for Unix (don't forget that Mac OS X is a Unix system now). ClamAV has been susceptible to multiple buffer overflow-triggered situations of arbitrary code execution since 2005, and this appears to be the latest incident.

One serious situation with the Mac System software itself which the 2008-007 security patch does address, involves what Apple describes as an independent discovery regarding maliciously crafted files and the Finder program. On a Mac, a file can be responsible for generating its own icon in Finder; the content of that icon is part of the file's "resource fork." Malicious code in the icon portion can cause Finder to shut down; and when it tries to restart, naturally, it tries rendering the same icon again. Which causes it to shut down again, which ends up making Finder look like something you saw in a Mac commercial once...on the left side of the TV screen.

While all this stopping and restarting is going on, Finder can lose track of the active user's own account. So this latest patch spawns a separate process for generating icons, which then links back to Finder.

Package 2008-007 also contains fixes for vulnerabilities in MySQL Server, Apache, PHP, and Tomcat.

Add a Comment

9 Comments

Name E-mail

Betanews reserves the right to remove any comment at any time for any reason. Please keep your responses appropriate and on topic. Foul language and personal attacks will not be tolerated.

Jeez, why would anyone want to hurt our beloved Apple OS X? These are sad times :(

Score: 0

|

Not to worry, with a Mac there is only so much damage you can do. The silly crap you see on a PC like turning hundreds of thousands of infected computers into spamming machines and completely taking over a Mac is something you will never witness.

Apple is all about security at it's core, that is why the Macintosh is built on UNIX. Security is already baked in. All Apple has to do is keep updating the Mac. No need for bloated and memory hogging antivirus.

Score: 0

|

This is exactly the reason security attacks are pointless on a Mac, Apple is always on top of security, producing the most rock solid and secure OS on the planet.

Score: 0

|

I'm bored of this style of trolling.

Score: 0

|

pookie put the pipe down

Score: 0

|

I think this is a bad attempt at sarcasm.

Score: 0

|

There goes those gas fumes in the basement messing with your head again lol.

Score: 0

|

LOL

Time for him to check the batteries in his carbon monoxide detectors. :)

Score: 0

|

I wonder if ClamAV for Mac is as useless as the other versions. No real-time shield = fail.

Score: 0

|

Tiny netbooks, simple video set Sony sailing through CES

It's only the first set of Sony announcements, but the product assortment at...

Live from the Panasonic press conference

No longer "Matsushita," and given a big boost with the pending acquisition of...

Sony's big news: the Vaio P 'Lifestyle PC'

The question in advance of Sony's first press conference at CES (there will...

Samsung shows slimmer LED TVs, slimmer Blu-ray console

In an era when HDTVs are being measured in terms of pinky-width, Samsung...

Sharp stays (mostly) on point at lunchtime CES event

A very big room, journalists on the feedbag, and the tricky task of pitching...

Audiovox flashback features Elvis and rabbit-ears

Elvis! The season's first sighting of the King occurred at the Audiovox press...

Live from the Cisco press conference at CES 2009

Known worldwide as an infrastructure company, Cisco now plays a bigger role...

Toshiba focuses on mid-range DTV for everyone

Toshiba's press conference at CES 2009 this morning featured announcements in...

LG unleashes its annual flood of announcements

Holding down its traditional CES-opening spot at 8:00 am, LG on Wednesday ran...

Netgear debuts a BitTorrent-enabled set-top box

The first of NetGear's three big product announcements at CES this morning is...

Live from the LG press conference at CES 2009

Speaking to an overflow crowd in Las Vegas Wednesday morning, executives from...

CES Unveiled event provides a high-energy opener

If CES is a banquet, CES Unveiled -- the opening press event -- is like a...