• On MovieTome: See the TRAILER for TERMINATOR 4!

March 13, 2006 4:15 PM PST

Apple corrects patch trouble

Related Stories

Mac OS X patch faces scrutiny

March 7, 2006

Apple patches serious Mac OS flaws

March 1, 2006

Mac OS flaw exposes Apple users

February 21, 2006

Bluetooth worm targets Mac OS X

February 17, 2006
Apple Computer on Monday released the second set of Mac OS X security fixes in two weeks.

Security Update 2006-002 corrects problems caused by the company's previous patch and fixes newly discovered security flaws, some of which could let an attacker run code on a computer with the same privileges as the user, the company said on its Web site.

"This Security Update includes some upgrades to our download validation mechanism and strengthens it," Bud Tribble, Apple's vice president of software technology, told CNET News.com. "We reduced the number of false positives it gives."

Earlier this month Apple released a security update for its operating system to plug 20 holes. That update added download validation to the Safari Web browser, Apple Mail client and iChat instant-messaging tool. The function warns people that a download could be malicious when they click on the link.

However, download validation has been sounding the alarm on harmless files. "Security Update 2006-001 could cause the user to be warned when provided with certain safe file types, such as Word documents, and folders containing custom icons," Apple said in its security alert. The new update fixes that problem, the company said.

Additionally, Apple's previous update didn't entirely fix the problem. Malicious files could still run without any user action, Apple said. "This update provides additional checks to identify variations of the malicious file types addressed in Security Update 2006-001 so that they are not automatically opened," according to the alert.

The earlier patch also introduced errors with the PHP scripted programming language and "rsync" file transfer utility, Apple said. The PHP issue may prevent SquirrelMail from running and the rsync "--delete" command may not work, the company said. That is now corrected.

The new security update also fixes a pair of newly discovered flaws. One bug is a buffer overflow error in Apple Mail that could be triggered by enticing a user to double click on an e-mail attachment, Apple said. The bug could let an attacker run code in the context of the user, the company said.

The second flaw is related to how Mac OS X handles documents that contain JavaScript. An attacker could craft a file and host it on a remote Web site that would bypass certain access restrictions on a Mac when opened, according to Apple's advisory.

Security-monitoring company Secunia rates Apple's new fix "extremely critical," its highest-risk rating that's not often awarded.

While Apple urges its users to install the patches, there is no immediate risk of attack, Tribble said. "None of these issues are things where there are exploits in the wild," he said. "In a way you can say these are pre-emptive fixes to prevent problems from arising."

The new patch comes after weeks of scrutiny of the safety of OS X, prompted by the discovery of two worms and the disclosure of a serious vulnerability. Security experts also were questioning the effectiveness of Apple's latest patch, suggesting the company should add protection at a deeper level in the system.

Security Update 2006-002 can be downloaded and installed via the Software Update feature in Mac OS X or from Apple Downloads.

See more CNET content tagged:
Apple Computer, Apple Mac OS X, patch, attacker, Apple Mac OS

Add a Comment (Log in or register) 23 comments (Showing first 20 comments)
A Fast Response
by CBSTV March 13, 2006 5:40 PM PST
I'm impressed how quickly Apple responds with their Security
Updates.
Reply to this comment View reply
2 staged responses / Very Cool
by wysiwyg22 March 13, 2006 6:23 PM PST
I'm especially impressed that they released fixes in two stages. Stage one, just something to "Work" and prevent attackers from taking advantage once the flaw was publically released, then a second release as soon as a polished fix was in place.

Most software companies hardly get past stage one.
Reply to this comment
Apple apologists are unbelievable
by catch23 March 13, 2006 7:00 PM PST
Apple releases a ?fix? that doesn?t work, and you guys praise them?
Look, you can **** in a glass and call it Champaign while you toast one another on their wonderful deeds, but at the end of the day it was a total screw-up, both the original problem and the first fix. You same dumb idiots go off on MS when they pull this type of crap, so lets start believing that one set of standards is enough
Reply to this comment View reply
'Preemptive' says it all
by J.G. March 14, 2006 5:12 AM PST
I'm satisfied. Even Mac-gasmic, JM. Most of the vulnerabilities
never applied to my OS X installation anyway. Squirrel Mail?
Please. I don't even use Mail mail. And, as the Apple spokesman
said (it should have been at the beginning of the article, not the
bottom) there was nothing exploitable.

Why the weird Wintel types want Mac users to be unhappy with our
systems is beyond me.
Reply to this comment View reply
Latest Patch
by March 14, 2006 6:38 AM PST
I just downloaded the latest OSX security patch last night for my G5 iMac. I tried to start my computer this morning and NOTHING. It's fried. I have to admit, no hackers will be on my system for quite awhile.
Reply to this comment View all 3 replies
I know It's bad form to post external links
by Bob Brinkman March 14, 2006 7:08 AM PST
But this sums up the argument that is going to ensue way better then I could (requires sound)

http://badmash.tv/movies.php?v=bat

Why say it yourself when some one else said it better?
Reply to this comment
Latest patch is pack of trouble
by Eric Westra March 14, 2006 9:59 AM PST
Security Update 2006-002 has had multiple, serious implications
for many OSX users. I've seen reports from missing desktop icons,
to unusable hyperlinks in mail and applications, to complete
system meltdowns.

Some security patch. I wonder if Apple's quality control is slipping.
Reply to this comment View reply
free crap
by benjiernmd March 15, 2006 8:56 AM PST
Well, at least you won't be paying for the snafu that Apple made,
when other companies charge you for fixes that do not really work.
But then again, crap is a crap, free or not. Just choose the lesser
evil.
Reply to this comment
by lsawell July 14, 2008 4:57 PM PDT
27 hours ago I downloaded the latest Apple patch/update on my Power Mac G4. It went thru the process and went into restart mode. 30 hours later it's still on the grey page with the black apple siloette and the little thinking wheel is still going around and around. What's up with that? all attempts to recover have failed. The little wheel just keeps on spinning. Is it the eprom battery or a shot drive or what? Does anybody know how to recover from this problem?
Reply to this comment
 See all 23 Comments >>
Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from CNET News sponsors
You Need The Speed of Norton 2009
Introducing Norton Internet Security™2009

Click Here!
With one-click, one-minute install, under 8MB of memory usage and fewer, shorter scans, it's the fastest security suite anywhere. Norton. Smart Security, Engineered for Speed. Get a FREE trial today!

Click Here!
The Fastest Security Suite Anywhere

Experience the revolutionary Norton Internet Security™ 2009. With Norton™ Insight, a new feature, you get precision security that targets only at risk files for fewer, faster, shorter scans

Win a Trip to Space!*

Enter the Blast Off with Norton Sweepstakes for your shot at a trip to space. You could experience being fast and weightless, just like the new Norton 2009. *No purchase necessary; click for full details.

FREE Trial!

Act now to get your FREE trial of Norton Internet Security 2009. Try it for the protection. Love it for the speed

Norton Safe Web NEW!

A community-based system that rates web site safety

Norton Labs NEW!

Users can download new security technologies and share input directly with developers. Help us shape our future products!

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right