Apple worm
A flaw in the OS X CoreGraphics component is the most serious

Apple issues 13 security fixes

Problems with CoreGraphics, Fetchmail, iChat and mDNSResponder

Written by Shaun Nichols in California

Apple has issued security fixes for 13 components of its OS X operating system. 

A flaw in the OS X CoreGraphics component is the most serious, as it could allow an attacker to remotely execute code through a specially-crafted PDF file. The vulnerability only affects OS X 10.4.9 and OS X Server 10.4.9.

Apple did not say whether the code execution is confined to the limited privileges of the current user, or whether attackers could execute code at the root level.

Attackers could also target OS X's 'file' for remote code execution. This vulnerability affects all versions of Mac OS X 10.3 and 10.4. No other components suffered from remote execution vulnerabilities.

A flaw in Fetchmail could allow attackers to steal a user's email password. Fetchmail is used to download emails into a user's local machine, and Apple said that the component may not adequately encrypt the password.

Vulnerabilities in Apple's iChat messaging software and mDNSResponder were also patched. Both vulnerabilities could be exploited to remotely execute code, but would require the attacker to be on a local network with the target machine.

Apple also fixed a vulnerability in the way that OS X handles disk images. By convincing a user to mount two identically-named disk images, an attacker could disguise a piece of malicious software as a legitimate application or document.

The security update is available through Apple's software update system component or as a download from the company's website.

Tags:

Further reading

Apple iPhone gets thumbs-up from FCC

Federal Communications Commission approves Apple mobile for use   More...

iGasm ad rubs Apple up the wrong way

Legal eagles circle over Ann Summers stunt   More...

Users sue Apple over screen quality

Company accused of misleading advertising   More...

Hoax email knocks $4bn off Apple's bottom line

Stock market jittery on Apple valuation   More...

Related articles

Worm 'proves' Macs as vulnerable as PCs

Anonymous hacker boasts of attack that can penetrate fully-patched Macs   More...

Mega Apple patch fixes iPhone, Safari, OS X bugs

Update repairs 54 vulnerabilities   More...

Windows 2000 flaw highlights slow Patch Tuesday

Vista and XP spared from most dangerous vulnerabilities   More...

Four more fixes for Windows Safari

Security updates pile up for Apple browser   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

16 May 2008

2.97 MBXP on OLPC, broken dreams and Yahoo fights back More...

15 May 2008

3.28 MBDark fibre, mobile TV and solar power More...

14 May 2008

2.66 MBOnline inequality, mobile thumbprints and corporate raids More...

Poll

HOME WORKING

HOME WORKING

Do you let any or all of your employees work from home?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

OLPC

OLPC to ship with Windows XP

Microsoft teams up with One Laptop per Child project   More...

The Sims

The Sims goes flat-pack with Ikea

Virtual world gets Swedish wood   More...

Advertisement

Microsoft-Yahoo

Yahoo board fights back at Icahn

Investor accused of 'significant misunderstanding' in Microsoft saga   More...

MySpace

Woman charged over MySpace suicide

Lori Drew indicted on federal charges   More...

Advertisement