Welcome to PcMacZone - For Mac & PC Support and Information

Donat o Meter
HELP KEEP OUR SERVERS ONLINE!
Make donations with PayPal!
Donat-o-Meter Stats
September´s Goal: $100.00
Due Date:   Sep 30
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00

©
Donations

Menu
· Home
· Donations
· Downloads
· Feedback
· Film Reviews
· FORUM
· Private Messages
· Recommend Us
· Search
· Stories Archive
· Submit News
· Surveys
· Wallpapers
· Web Links
· Your Account

Latest Forums Posts

 PHP version upgrade
 Advertising standards in UK
 Play Station 3 hack available at . . . .
 HostPay details
 prices reduced
 I'm Looking for a netbook
 Anyone got a modded Xbox 360 they want to part with ?
 Any camera buffs on the forum?
 any mac users
 anybody now anything about Heart API?

PcMacZone - For Mac & PC Support and Information Forums


It's Happened To Every Great Civilization

Aion
120x600

 
Apple News Apple plugs critical security holes
Posted bymaximus on Thursday, January 21 @ 08:22:02 GMT
Contributed by maximus

Apple’s first Mac OS X security update for 2010 is out, providing cover for at least 12 serious vulnerabilities.

The update, rated critical, plugs security holes that could lead to code execution vulnerabilities if a Mac user is tricked into opening audio files or surfing to a rigged Web site.

With Security Update 2010-001, Apple also fixes flaws in the Adobe Flash Player plug-in that ships with the operating system.

Here’s what has been patched:

* CoreAudio (CVE-2010-0036) — A buffer overflow exists in the handling of mp4 audio files. Playing a maliciously crafted mp4 audio file may lead to an unexpected application termination or arbitrary code execution.

* Flash Player plug-in (7 vulnerabilities) — Multiple issues exist in the Adobe Flash Player plug-in, the most serious of which may lead to arbitrary code execution when viewing a maliciously crafted web site. The issues are addressed by updating the Flash Player plug-in to version 10.0.42.

* ImageIO (CVE-2009-2285) — A buffer underflow exists in ImageIO’s handling of TIFF images. Viewing a maliciously crafted TIFF image may lead to an unexpected application termination or arbitrary code execution.

* Image RAW (CVE-2010-0037) — A buffer overflow exists in Image RAW’s handling of DNG

* images. Viewing a maliciously crafted DNG image may lead to an unexpected application termination or arbitrary code execution.

* OpenSSL (CVE-2009-3555) — A man-in-the-middle vulnerability exists in the SSL and TLS protocols. Further information is available here. A change to the renegotiation protocol is underway within the IETF. This update disables renegotiation in OpenSSL as a preventive security measure. The issue does not affect services using Secure Transport as it does not support renegotiation.

The update is being distributed via Apple’s Software Update mechanism.


 
Login
Nickname

Password

Security Code: Security Code
Type Security Code

Don't have an account yet? You can create one. As a registered user you have some advantages like theme manager, comments configuration and post comments with your name.

Related Links
· More about Apple News
· News by maximus


Most read story about Apple News:
Psystar shut down by Apple....or are they?


Article Rating
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Excellent
Very Good
Good
Regular
Bad


Options

 Printer Friendly Printer Friendly


Associated Topics

Apple News

PHP-Nuke Copyright © 2005 by Francisco Burzi. This is free software, and you may redistribute it under the GPL. PHP-Nuke comes with absolutely no warranty, for details, see the license.
Page Generation: 0.26 Seconds