Tuesday, March 13, 2007

Apple Issues Megapatch

Via CNET.com -

The megapatch is the seventh Apple security patch release in three months. It deals with vulnerabilities in Apple's own software, as well as third-party components such as Adobe Systems' Flash Player, OpenSSH and MySQL. Sixteen of the vulnerabilities addressed by the update were previously released as part of two high-profile bug-hunting campaigns.

The vulnerabilities pose varying risks to Macs. Several of the flaws could be exploited to gain full control over a Mac running the vulnerable component, according to Apple's advisory. Other holes are limited and could only be exploited to crash a Mac or used by somebody who already has access to a machine to elevate privileges, for example.

-----------------------------------------

It looks like Apple has finally updated its OpenSSH to v4.5....even tho that this version was released by the open source world back in Nov 2006. This update fixes multiple vulnerabilities in OpenSSH, the most serious of which is arbitrary code execution.

Apple updated its GNU Tar to version 1.16.1, which was released by the open source world back in Dec 2006.

Apple updated its MySQL Server to version 4.1.22, which was released by the open source world back in Nov 2006.

Apple updated its Sudo to version 1.6.8.p12, which was released by the open source world back in Nov 2005.

No comments:

Post a Comment