Apple
Buffer overflow vulnerabilities could allow an attacker to take control

Apple plugs ten 'critical' security holes

More fixes for OS X

Written by Tom Sanders in California

Apple has released a security update for its OS X 10.3 and OS X 10.4 operating systems.

The patch fixes vulnerabilities in the operating system itself as well as bundled applications.

Apple does not provide severity ratings for the flaws in its software, but an advisory from security website Secunia gave the vulnerabilities its second highest rating of 'highly critical'. 

The patch repairs a buffer overflow vulnerability in ImageIO, a Java tool used to display images. The security hole could allow an attacker to take control of a system by placing a specially crafted Gif image on a website.

Apple's Quickdraw manager is also susceptible to a buffer overflow attack through the use of a specially crafted Pict image. The tool is used by several applications, including Safari, Mail and Finder.

Other vulnerabilities patched in the update include Apple's Mail application, the Safari browser and the Quicktime Media player.

Mimicking Microsoft's 'patch Tuesday' release cycle, Apple usually releases security updates at midnight on the second Tuesday of the month.

This cycle is not official policy, however, and this month the vendor released its patch nine days later.

Microsoft did not release any patches in September, pulling a previously announced critical update because of "quality concerns".

Users can download the 7.1Mb Apple patch through the software update feature in the operating system or from the Apple website here

Tags:

Further reading

Apple adopts controversial security chip

Trusted Platform Module limits OS X to Macs, but could do more   More...

Hackers set OS X free from Apple

Operating system brought to PCs against Apple's wishes   More...

Apple unveils OS X security patches

Denial of service and file overwrite bugs fixed   More...

Apple OS X update breaks 64-bit applications

Missing library leaves 64-bit applications in the cold   More...

Related articles

QuickTime flaw adds to Apple's woes

Exploit especially dangerous for Firefox users   More...

Apple patches streaming media flaw

Quicktime hole targeted by attackers   More...

Apple patches critical QuickTime flaws

Vulnerabilities could lead to remote code execution   More...

Apple patches critical Safari holes

Four flaws addressed in latest update   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

08 Jul 2008

3.67 MBSafe browsing, voice recognition and cyber-criminals More...

07 Jul 2008

2.76 MBLaptops on holiday, gaming in Vietnam and 'unbreakable' encryption More...

04 Jul 2008

5.51 MBPodcast Special: Views from the Valley More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Firefox

Firefox users shown to be safer

Internet Explorer users the worst of the bunch   More...

Internet Corporation for Assigned Names and Numbers

Icann downplays recent site hacks

Redirects were 'limited', says organisation   More...

Advertisement

DNA

Boffins build artificial DNA

Could be used in the ultimate computer   More...

Microsoft

Microsoft outlines appeal against EU fine

Two sides back in court   More...

Advertisement