Apple Patches 31 Security Holes
- http://blog.washingtonpost.com/securityfix…security_1.html
November 28, 2006; 6:03 PM ET
"…Users can download the free updates using OS X's Software Update feature*, or directly from Apple Downloads**…"
Security Update 2007-001
- http://docs.info.apple.com/article.html?artnum=304989
"…QuickTime
CVE-ID: CVE-2007-0015
Available for: QuickTime 7.1.3 on Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.8, Mac OS X Server v10.4.8, Windows XP/2000(*)
Impact: Visiting malicious websites may lead to arbitrary code execution
Description: A buffer overflow exists in QuickTime's handling of RTSP URLs. By enticing a user to access a maliciously-crafted RTSP URL, an attacker can trigger the buffer overflow, which may lead to arbitrary code execution. A QTL file that triggers this issue has been published on the Month of Apple Bugs web site (MOAB-01-01-2007). This update addresses the issue by performing additional validation of RTSP URLs."
* > http://www.kb.cert.org/vuls/id/442497
Last Updated: 01/23/2007 ~ "…Apple has issued an update to this issue. See Apple Security Update 2007-001. This update appears to apply only to systems running Mac OS X. It is -not- clear that an update for Windows systems is available as of 2007-01-23…"
AirPort Extreme Update 2007-001
- http://docs.info.apple.com/article.html?artnum=305031
* AirPort
CVE-ID: CVE-2006-6292
Available for: Mac OS X v10.4.8, Mac OS X Server v10.4.8
Impact: Attackers on the wireless network may cause system crashes
Description: An out-of-bounds memory read may occur while handling wireless frames. An attacker in local proximity may be able to trigger a system crash by sending a maliciously-crafted frame to an affected system. This issue affects the Core Duo version of Mac mini, MacBook, and MacBook Pro computers equipped with wireless. Other systems, including the Core 2 Duo versions are not affected. This update addresses the issue by performing additional validation of wireless frames. Credit to LMH for reporting this issue."