What the Tech logo
Welcome! Register for a free account (or login) > How does it work?
  1. Quickly register. It will only take 60 seconds.
  2. Start a new topic. Ask your question. Wait for an email reply.
  3. Is your system infected? Begin reading the malware removal guide.
register button
3 Pages V  < 1 2 3 >  
Reply to this topicStart new topic
> Apple Mac OS X updates
AplusWebMaster
post May 24 2008, 06:08 AM
Post #16


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,565
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

Java for Mac OS X 10.5 Update 1
- http://www.apple.com/support/downloads/
This Java for Mac OS X 10.5 Update 1 adds
Java SE 6 version 1.6.0_05 to your Mac.


.
Go to the top of the page
 
+Quote Post
AplusWebMaster
post May 28 2008, 06:17 PM
Post #17


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,565
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

Mac OS X 10.5.3 Update / 2008-003
- http://www.apple.com/downloads/macosx/appl...1053update.html
May 28, 2008

Security Updates
- http://support.apple.com/kb/HT1222

Security Update 2008-003 / Mac OS X 10.5.3
- http://support.apple.com/kb/HT1897

- http://secunia.com/advisories/30430/
Release Date: 2008-05-29
Critical: Highly critical
Impact: Security Bypass, Cross Site Scripting, Exposure of system information, Exposure of sensitive information, Privilege escalation, DoS, System access
Where: From remote
Solution Status: Vendor Patch
OS: Apple Macintosh OS X ...
Solution: Update to Mac OS X 10.5.3 or apply Security Update 2008-003...


This post has been edited by AplusWebMaster: May 29 2008, 05:07 AM
Go to the top of the page
 
+Quote Post
AplusWebMaster
post Jul 1 2008, 10:08 AM
Post #18


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,565
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

Security Update 2008-004 and Mac OS X 10.5.4
- http://support.apple.com/kb/HT2163
Last Modified: June 30, 2008
Article: HT2163

Safari 3.1.2 for Mac OS X 10.4.11
- http://support.apple.com/kb/HT2165
Last Modified: June 30, 2008
Article: HT2165

- http://isc.sans.org/diary.html?storyid=4651
Last Updated: 2008-07-01 17:17:35 UTC ...(Version: 2) - "...One thing interesting that is not fixed, is the Apple Remote Desktop vuln..."

.

This post has been edited by AplusWebMaster: Jul 1 2008, 11:35 AM
Reason for edit: Added ISC notes...
Go to the top of the page
 
+Quote Post
AplusWebMaster
post Aug 1 2008, 03:45 AM
Post #19


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,565
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

Apple Security Update 2008-005...
- http://isc.sans.org/diary.html?storyid=4810
Last Updated: 2008-08-01 08:27:35 UTC - "Apple released their patch overnight... Most importantly it contains the workaround for the DNS bug CVE-2008-1447. Also included is an upgrade to PHP 5.2.6 (which was released in source code at http://www.php.net/ on May 1st). Seems we all need to urge Job's gang to release patches significantly faster: it's the price to pay to base parts of your system on open source code. Apple Mac OS X users get it though software update. As always it's one big patch, given that little choice, you'll want to PATCH NOW."

- http://support.apple.com/kb/HT2647
August 01, 2008

- http://www.apple.com/support/downloads/
07/31/2008

- http://secunia.com/advisories/31326/
Release Date: 2008-08-01
Critical: Highly critical
Impact: Security Bypass, Spoofing, Privilege escalation, DoS, System access
Where: From remote
Solution Status: Vendor Patch
OS: Apple Macintosh OS X ...
Solution: Apply Security Update 2008-005...

---

- http://isc.sans.org/diary.html?storyid=4810
Last Updated: 2008-08-01 20:06:50 UTC ...(Version: 3) "...UPDATE ...Apple might have fixed some of the more important parts for servers, but is far from done yet as all the clients linked against a DNS client library still need to get the workaround for the protocol weakness..."

//

This post has been edited by AplusWebMaster: Aug 2 2008, 07:11 AM
Reason for edit: Added Secunia advisory, ISC update...
Go to the top of the page
 
+Quote Post
AplusWebMaster
post Sep 15 2008, 05:16 PM
Post #20


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,565
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

Mac OSX 10.5.5 and Security Update 2008-006
- http://isc.sans.org/diary.html?storyid=5041
Last Updated: 2008-09-15 21:51:39 UTC - "...Apple released OSX update 10.5.5*. Built into 10.5.5 is Security Update 2008-006**, marking the 6th major security update of the year. So aside from the ton of updates in 10.5.5 for OSX Leopard, check out the below updates included with it. Keep in mind that Security Update is not just for 10.5 (OSX Leopard), being that it is also available for 10.4, Desktop and Server releases..."

* http://support.apple.com/kb/HT2405
"...Choose Software Update from the Apple menu to automatically check for the latest Apple software via the Internet, including this update..."

** http://support.apple.com/kb/HT3137

- http://www.theregister.co.uk/2008/09/16/ap...ty_update_sept/
16 September 2008 - "...Both updates mend DNS security holes in older versions of BIND previously bundled with Apple's software..."

- http://secunia.com/advisories/31882/
Release Date: 2008-09-16
Critical: Highly critical
Impact: Security Bypass, Cross Site Scripting, Spoofing, Manipulation of data, Exposure of system information, Exposure of sensitive information, DoS, System access
Where: From remote
Solution Status: Vendor Patch ...

ph34r.gif

This post has been edited by AplusWebMaster: Sep 16 2008, 08:03 AM
Reason for edit: Added Secunia advisory...
Go to the top of the page
 
+Quote Post
AplusWebMaster
post Sep 25 2008, 08:42 AM
Post #21


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,565
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

Mac OS X Java multiple vulns - update available
- http://secunia.com/advisories/32018/
Critical: Highly critical
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, DoS, System access
Where: From remote
Solution Status: Vendor Patch
OS: Apple Macintosh OS X
...Some vulnerabilities in Java 1.4.2_16 and Java 1.5.0_13 can be exploited by malicious people to cause a DoS (Denial of Service), to bypass certain security restrictions, disclose system information or potentially sensitive information, or to compromise a vulnerable system...
Solution:
-- Java for Mac OS X 10.4 --
Update to Release 7:
http://www.apple.com/support/downloads/jav...04release7.html
-- Java for Mac OS X 10.5 --
Apply Update 2:
http://www.apple.com/support/downloads/jav...105update2.html ...
Original Advisory: Apple:
http://support.apple.com/kb/HT3179
http://support.apple.com/kb/HT3178

http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-1185
http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-1186
http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-1187
http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-1188
http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-1189
http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-1190
http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-1191
http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-1192
http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-1193
http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-1194
http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-1195
http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-1196
http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-3103
http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-3104
http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-3105
http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-3106
http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-3107
http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-3108
http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-3109
http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-3110
http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-3111
http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-3112
http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-3113
http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-3114
http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-3115
http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-3637
http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-3638

ph34r.gif

This post has been edited by AplusWebMaster: Sep 27 2008, 05:58 AM
Reason for edit: Added CVE ref links...
Go to the top of the page
 
+Quote Post
AplusWebMaster
post Oct 10 2008, 07:35 AM
Post #22


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,565
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

Apple Mac OS X Security Update 2008-007 released
- http://secunia.com/advisories/32222/
Release Date: 2008-10-10
Critical: Moderately critical
Impact: Security Bypass, Cross Site Scripting, Manipulation of data, Exposure of system information, Exposure of sensitive information, Privilege escalation, DoS, System access
Where: From remote
Solution Status: Vendor Patch
OS: Apple Macintosh OS X...
Original Advisory: Apple Security Update 2008-007:
http://support.apple.com/kb/HT3216

> http://www.apple.com/support/downloads/

ph34r.gif
Go to the top of the page
 
+Quote Post
AplusWebMaster
post Nov 11 2008, 07:45 AM
Post #23


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,565
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

Apple fixes three iLife flaws - Mac OS v10.4.9 through v10.4.11
- http://news.cnet.com/8300-1009_3-83.html
November 10, 2008 - "Apple released an update on Monday for iLife 8.0 and Aperture 2 running on Mac OS v10.4.9 through v10.4.11. The update does -not- affect those running Mac OS X v10.5.5. The update affects system software components shared by all iLife '08 applications and, in most cases, the specific vulnerabilities could lead to application termination or arbitrary code execution. iLife Support 8.3.1 may be obtained from the Software Update pane in System Preferences -or- Apple's Software Downloads* Web site..."
* http://www.apple.com/support/downloads/

- http://support.apple.com/kb/HT3276

- http://secunia.com/advisories/32688/
Release Date: 2008-11-12
Critical: Highly critical
Impact: DoS, System access
Where: From remote
Solution Status: Vendor Patch
Software: Apple Aperture 2.x, Apple iLife 8.x
...The vulnerabilities are reported in Apple iLife 8.0 and Aperture 2 on Mac OS 10.4.9 through 10.4.11.
Solution: Apply iLife Support 8.3.1.
http://www.apple.com/support/downloads/ilifesupport831.html

ph34r.gif

This post has been edited by AplusWebMaster: Nov 12 2008, 06:43 AM
Go to the top of the page
 
+Quote Post
AplusWebMaster
post Dec 15 2008, 02:17 PM
Post #24


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,565
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

Apple OSX 10.5.6 - Security update 2008-008
- http://isc.sans.org/diary.html?storyid=5488
Last Updated: 2008-12-15 18:25:13 UTC - "Apple's released an update for OSX, you can now download 10.5.6 through the Software Update app. It patches a large number of vulns*..."

> http://support.apple.com/downloads/
Mac OS X 10.5.6 Update
The 10.5.6 Update is recommended for all users running Mac OS X Leopard...

* http://support.apple.com/kb/HT3338
December 15, 2008

ph34r.gif
Go to the top of the page
 
+Quote Post
AplusWebMaster
post Dec 20 2008, 01:19 PM
Post #25


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,565
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

- http://www.theinquirer.net/inquirer/news/1...pgrade-problems
19 December 2008 - "... In a support document posted to its site*, Apple said that the problem was caused by an incomplete update getting seeded into the Software Update process... According to Apple, you should force Software Update to quit, remove the partial update from your library, and re-download the update. The combo update that was offered at the same time was more stable than the stand-alone update, apparently."

Mac OS X 10.5: Software Update stops responding during "Configuring installation"
- http://support.apple.com/kb/TS2383
Last Modified: December 18, 2008

blink.gif ph34r.gif
Go to the top of the page
 
+Quote Post
AplusWebMaster
post Feb 12 2009, 06:35 PM
Post #26


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,565
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

Apple Security Updates
- http://isc.sans.org/diary.html?storyid=5848
Last Updated: 2009-02-12 23:37:34 UTC ...(Version: 2) - "Apple today released a number of security updates:
1 - Safari for Windows
This update will bring Safari up ot version 3.2.2. It fixes a vulnerability within Safari which allows for the execution of Javascript in "feed:" URLs.
Safari 3.2.2 for Windows: http://support.apple.com/kb/HT3439
- http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2009-0137
CVSS v2 Base Score: 10.0 (HIGH)

2 - OS X Update 2009-001
The first security update from Apple for 2009. It fixes a huge number of issues (I counted 45 CVE numbers). Many of them are in X11, perl and python. This patch includes the Safari patch mentioned above.

3 - Java update for OS X
And lastly: Apple also released a patched version of java, which will bring Java up to version 8 for OS X 10.4 (Tiger... not Leopard). For Leopard (OS X 10.5), Java update 3 was released today as well.
See:
- http://support.apple.com/kb/HT1222
- http://support.apple.com/downloads/

OS X Security Update
- http://secunia.com/advisories/33937/
Release Date: 2009-02-13
Critical: Highly critical
Impact: Unknown, Security Bypass, Exposure of sensitive information, Privilege escalation, DoS, System access
Where: From remote
Solution Status: Vendor Patch ...
Original Advisory: http://support.apple.com/kb/HT3438 ...

OS X update for Java
- http://secunia.com/advisories/33935/
Release Date: 2009-02-13
Critical: Highly critical
Impact: Security Bypass, Exposure of sensitive information, System access
Where: From remote
Solution Status: Vendor Patch...
Original Advisory: Apple:
http://support.apple.com/kb/HT3436
http://support.apple.com/kb/HT3437 ...

.

This post has been edited by AplusWebMaster: Feb 13 2009, 12:26 PM
Go to the top of the page
 
+Quote Post
AplusWebMaster
post Mar 7 2009, 10:10 AM
Post #27


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,565
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

Apple Airport Extreme / Time Capsule multiple vulns - updates available
- http://secunia.com/advisories/34105/2/
Release Date: 2009-03-06
Critical: Moderately critical
Impact: Spoofing, Exposure of sensitive information, DoS
Where: From remote
Solution Status: Vendor Patch
OS: Apple Airport Extreme, Apple Time Capsule ...
Solution: Update to firmware version 7.4.1...
Original Advisory: HT3467:
http://support.apple.com/kb/HT3467 ...

- http://support.apple.com/downloads/

Apple security updates (index)
- http://support.apple.com/kb/HT1222

ph34r.gif

This post has been edited by AplusWebMaster: Mar 13 2009, 10:36 AM
Go to the top of the page
 
+Quote Post
AplusWebMaster
post May 12 2009, 09:01 PM
Post #28


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,565
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

Apple OS X 10.5.7 update / Security update 2009-002
- http://support.apple.com/kb/HT3397
May 12, 2009

About the security content of Security Update 2009-002 / Mac OS X v10.5.7
- http://support.apple.com/kb/HT3549
May 12, 2009

- http://www.f-secure.com/weblog/archives/00001681.html
"... fixes 67 security issues in OS X..."

- http://lists.apple.com/archives/security-a...y/msg00002.html
May 12, 2009

• Safari 4 beta: http://support.apple.com/kb/HT3551
o libxml: CVE-2008-3529
o Safari: CVE-2009-0162
o WebKit: CVE-2009-0945

• Safari 3.2.3: http://support.apple.com/kb/HT3550
o libxml: CVE-2008-3529
o Safari: CVE-2009-0162
o WebKit: CVE-2009-0945

- http://support.apple.com/downloads/
___

Mac OS X - Security Update 2009-002
- http://secunia.com/advisories/35074/2/
Release Date: 2009-05-13
Critical: Highly critical
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, Privilege escalation, DoS, System access

Safari
- http://secunia.com/advisories/35056/2/
Release Date: 2009-05-13
Critical: Highly critical

ISC notes on Mac updates...
- http://isc.sans.org/diary.html?storyid=6382
Last Updated: 2009-05-12 23:07:09 UTC

ph34r.gif

This post has been edited by AplusWebMaster: May 15 2009, 04:37 AM
Go to the top of the page
 
+Quote Post
AplusWebMaster
post Jun 9 2009, 12:30 AM
Post #29


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,565
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

Safari jumbo patch - 50+ fixes...
- http://blogs.zdnet.com/security/?p=3541
June 8, 2009 - "... The latest fixes, available in the new Safari 4.0, corrects a wide range of code execution and denial-of-service vulnerabilities and even comes with a fix for the vexing “clickjacking” issues plaguing modern Web browsers... The latest Safari refresh also fixes five documented several code execution issues in CoreGraphics (all could lead to complete computer takeover attacks); an ImageIO issue that could be exploited via maliciously crafted PNG images; 5 flaws in libxml; and a variety of WebKit vulnerabilities that affect Safari on both Mac and Windows systems..."
- http://support.apple.com/downloads/Safari_4

> http://support.apple.com/kb/HT3613

- http://secunia.com/advisories/35379/2/
Release Date: 2009-06-09
Critical: Highly critical
Impact: Exposure of sensitive information, System access
Where: From remote
Solution Status: Unpatched
Software: Safari 3.x, Safari for Windows 3.x ...
Solution: Upgrade to Safari version 4, which fixes the vulnerabilities...

ph34r.gif

This post has been edited by AplusWebMaster: Jun 9 2009, 07:13 AM
Go to the top of the page
 
+Quote Post
AplusWebMaster
post Jun 16 2009, 06:49 AM
Post #30


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,565
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

Mac OS X Java updates...
- http://support.apple.com/kb/HT1222
Java for Mac OS X 10.4 Release 9
15 June 2009
Java for Mac OS X 10.5 Update 4
15 June 2009

- http://support.apple.com/downloads/

Security content of Java for Mac OS X 10.4 Release 9
- http://support.apple.com/kb/HT3633

Security content of Java for Mac OS X 10.5 Update 4
- http://support.apple.com/kb/HT3632

- http://voices.washingtonpost.com/securityf...rss=securityfix
June 16, 2009 - "... This Java update appears to address most of the outstanding Java vulnerabilities. From looking at the common vulnerabilities and exposures (CVE) numbers attached to each of the flaws fixed by Apple's Java rollup, it looks like this update brings Mac OS X systems to the equivalent of Java 6 Update 13..."

ph34r.gif

This post has been edited by AplusWebMaster: Jun 16 2009, 10:19 AM
Go to the top of the page
 
+Quote Post

3 Pages V  < 1 2 3 >
Reply to this topicStart new topic

 


RSS Time is now: 17th March 2010 - 01:01 AM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
Memory Forums | Auto Repair Forum
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy