Mac OS X Leopard
Problems were uncovered in the way Leopard classifies its 'block all incoming connections' setting

Apple fixes Leopard firewall

New update addresses security issues

Written by Shaun Nichols in California

Apple has issued an update for its newly-released MacOS 10.5.1, better known as Leopard.

The update addresses Leopard's firewall, the most highly-publicised shortcoming in the operating system.

Shortly after Leopard's public release in October, researchers claimed that the firewall was not doing its job.

Heise Security researcher Jurgen Schmidt said that users would not be able to rely on the firewall to block potentially harmful traffic, even at its most secure setting.

Apple explained that the issues Schmidt had highlighted were down to the way Leopard classifies its 'block all incoming connections' setting.

When users select the option to block all incoming connections, processes running at the root level are not blocked by the firewall.

"The 'block all incoming connections' setting for the firewall is misleading, " Apple admitted.

Apple is changing the option from 'block all incoming connections' to 'allow only essential services' in an effort to provide a more accurate description.

Among the processes not blocked under the setting are components for DHCP network configurations, IPsec security protocols and Bonjour networking software.

The update will also provide the option to further enhance Leopard's firewall protection by allowing users to block all connections for a specific application, including root-level connections which had previously been allowed.

Apple also corrected an issue in which some firewall preferences would not take effect until certain process had been restarted.

The update only effects OS X Leopard. Users can obtain the update through the Apple Downloads site or through the OS X Software Update component.

Tags:

Further reading

Leopard users unable to run Java 1.6

Developers claim Java 6 absent from new Apple OS   More...

Mutant Trojans threaten Mac users

Malware authors tweaking payload, say researchers   More...

Mac Trojan attack gathers steam

OS X attack being served up with PC malware   More...

Phishing Trojan targets Mac OS X

Fake codec delivers Mac malware   More...

Related articles

Security expert mauls Leopard firewall

Researcher finds glaring holes in new Apple OS   More...

QuickTime flaw adds to Apple's woes

Exploit especially dangerous for Firefox users   More...

Mac Mail flaw resurfaces in Leopard

Flaw allows code to masquerade as images   More...

Apple unveils iPhone 2.0 software

Enterprise features to accompany SDK   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

25 Jul 2008

7.85 MBPodcast Special: Views from the Valley More...

24 Jul 2008

3.68 MBSpammer jailed, Esquire e-cover, and network passwords More...

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Credit card transaction

Credit card fraud rampant in the UK

Attempted frauds go unreported and ignored, analysts claim   More...

Intel

Intel rolls out new embedded line-up

System-on-a-chip offerings promise footprint and power saving   More...

Advertisement

Network cables

Tech giants collaborate on wireless HD

Another attempt at cable-free transmission in the home   More...

iPhone fever fills AT&T coffers

US provider cashes in on Apple smartphone   More...

Advertisement