Apple update fixes 'critical' security bug
Rumble in the jungle
2nd March 2006 13:00 GMT
Apple released a security update on Wednesday that fixes multiple vulnerabilities, including a critical flaw in its Safari web browser that created a means for hackers to attack vulnerable systems.
The security bug meant malicious hackers could rename "safe file" extensions stored in ZIP archives, creating a way to trick users into executing malicious shell scripts. The flaw meant malicious applications could appear as a safe file type. If Mac users had left the "Open safe files after downloading" option enabled in Safari then malware would automatically be executed as soon as a user was tricked into visiting a malicious-constructed website. Security researchers produced a proof of concept demo to validate their concerns about the critical flaw.
Apple's update tackles the issue by performing additional download validation so that the user is warned (in Mac OS X v10.4.5) or downloads are not automatically opened (in Mac OS X v10.3.9). The update also addresses 19 other security bugs in Mac OS X involving security flaws in Safari, the PHP Apache module and scripting environment as well as Mail and iChat security bugs, as summarised by Secunia here.
The appearance of the Safari bug, along with a brace of low to no risk worms affecting Mac OS X, spawned a lively debate between Mac fans and security vendors over the impact of the security flap, which disinterested observers judged to be largely academic. ®
Register Hardware » News » Mac


Apple 15.4" Macbook Pro Notebook (2.66GHz Intel Core 2 Duo Mobile, 4GB DDR3, 320GB HDD, DVDW DL, Mac OS X v10.5 Leopard, 15.4" LCD)
Apple 13.3" MacBook Pro Notebook (2.26GHz Intel Core 2 Duo Mobile, 2GB DDR3, 160GB HDD, DVD±RW DL, Mac OS X v10.5 Leopard, 13.3" LCD)
Apple MacBook MB881LL/A Notebook (2GHz Intel Core 2 Duo, 2GB DDR2, 120GB HDD, DVDRW DL, Mac OS X v10.5 Leopard, 13.3" LCD)
Apple 15.4" Macbook Pro Notebook (2.4GHz Intel Core 2 Duo, 2GB DDR3, 250GB, DVD±RW DL, Mac OS X v10.5 Leopard, 15.4" LCD)
Apple iMac Intel Core 2 Duo 24" Desktop (2.8GHz Intel Core 2 Duo, 2GB DDR2, 320GB, DVD±RW DL, Macintosh OS X 10.5 Leopard, 24" LCD)