Apple bug
Apple has issued a major security update for Mac OS X and Safari

Apple issues major OS X security update

Safari also patched

Written by Shaun Nichols in California

Apple has issued a major security update for Mac OS X and Safari. The update addresses 86 common vulnerability and exposure CVE entries in 30 applications for Mac OS.

Among the components addressed by the update are vulnerabilities in the Printing and Preview components which could allow encrypted PDF files to be viewed without authentication.

Other fixes include security updates for the ClamAV antivirus application, the OS X Leopard application firewall and several Apache components.

The Safari update addresses 13 security vulnerabilities, one of which could allow an attacker to remotely execute code on OS X, Windows XP and Windows Vista systems if exploited by an attacker.

Nine of the patched flaws could allow an attacker to conduct a cross-site scripting attack in which information entered into one page is transmitted to another site run by an attacker.

These vulnerabilities were found in the WebKit and WebCore components of the browser, as well as the elements of the browser that handle JavaScript and the error page.

Both the OS X and Safari updates can be downloaded automatically by way of Apple's Software Update tool or manually from the Apple Downloads site.

Further reading

Apple developers go crazy for iPhone

100,000 SDK downloads in four days   More...

Apple unveils iPhone 2.0 software

Enterprise features to accompany SDK   More...

Wozniak trashes iPhone and MacBook Air

Sounds of grinding teeth from Cupertino   More...

Inventor files iPhone patent suit

Caller ID is apparently patented   More...

Related articles

Mega Apple patch fixes iPhone, Safari, OS X bugs

Update repairs 54 vulnerabilities   More...

Apple patches critical Safari holes

Four flaws addressed in latest update   More...

Four more fixes for Windows Safari

Security updates pile up for Apple browser   More...

QuickTime flaw adds to Apple's woes

Exploit especially dangerous for Firefox users   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

09 May 2008

2.51 MBWiMax muddle, Google tactics and asteroid bunkum More...

08 May 2008

3.26 MBBroadband Anywhere, phone-free transport and Web 3.0 More...

07 May 2008

3.19 MBUK success, a paucity of IT women and robot wars More...

Poll

DATA ENCRYPTION

DATA ENCRYPTION

Should encryption be mandatory for all personal data held by companies and governments?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Ofcom

Ofcom outlines future wireless vision

Wi-Fi healthcare and intelligent car brakes in the pipeline   More...

HP

HP Labs opens doors to academia

Innovation Research Program invites proposals related to current research   More...

Advertisement

Asteroid

Nasa plans manned mission to asteroid

Bruce Willis thankfully not going   More...

MySpace

MySpace offers opt-in data sharing

Deals signed with Photobucket, Twitter, eBay and Yahoo   More...

Advertisement