E-Mail:

OS X 10.3.5 and Security Updates Released!

Apple released OS X 10.3.5 today, as well as a Security Update 2004-08-09.

First, if you do not want to upgrade to 10.3.5 right away, its still a good idea to install the SU 2004-08-09 since it corrects the libpng security holes that affects OS X, Windows, and Linux… A fix for Linux was up shortly after the holes were announced, and now OS X has a fix:

Security Update 2004-08-09 (Mac OS X 10.3.4 and Mac OS X 10.2.8)

· libpng (Portable Network Graphics) Fixes CAN-2002-1363, CAN-2004-0421, CAN-2004-0597, CAN-2004-0598, CAN-2004-0599

Impact: Malicious PNG images can cause application crashes and could execute arbitrary code

Description: A number of buffer overflows, null pointer dereferences and integer overflows have been discovered in the reference library for reading and writing PNG images. These vulnerabilities have been corrected in libpng which is used by the CoreGraphics and AppKit frameworks in Mac OS X. After installing this update, applications that use the PNG image format via these frameworks will be protected against these flaws.

To download the update, run Software Update from the Apple Menu or System Preferences… OR… Download it below:

>> Security Update 2004-08-09 (10.2.8)

>> Security Update 2004-08-09 (10.3.5)

If you want to upgrade to 10.3.5 right away, because you have absolutely no fear of it causing trouble on your system (no OS is perfect you know), then here is what has been changed:

Mac OS X 10.3.5

· libpng (Portable Network Graphics) Fixes CAN-2002-1363, CAN-2004-0421, CAN-2004-0597, CAN-2004-0598, CAN-2004-0599

Impact: Malicious PNG images can cause application crashes and could execute arbitrary code

Description: A number of buffer overflows, null pointer dereferences and integer overflows have been discovered in the reference library for reading and writing PNG images. These vulnerabilities have been corrected in libpng which is used by the CoreGraphics and AppKit frameworks in Mac OS X. After installing this update, applications that use the PNG image format via these frameworks will be protected against these flaws.

· Safari: Fixes CAN-2004-0743
Impact: In a special situation, navigation using the forward/backward buttons can re-send form data to a GET url.
Description: This is for a situation where a web form is sent to a server using a POST method which issues an HTTP redirect to a GET method url. Using the forward/backward buttons will cause Safari to re-POST the form data to the GET url. Safari has been modified so that in this situation forward/backward navigation will result in only a GET method.

· TCP/IP Networking: Fixes CAN-2004-0744
Impact: Maliciously crafted IP fragments can use too many system resources preventing normal network operation.
Description: The “Rose Attack” describes a specially constructed sequence of IP fragments designed to consume system resources. The TCP/IP implementation has been modified to limit the resources consumed and prevents this denial of service attack.

To download the update, run Software Update from the Apple Menu or System Preferences… OR… Download it below:

>> Mac OS X Update 10.3.5

>> Mac OS X Combined Update 10.3.5

Source for Security Information:

Apple’s Security Updates KB article.

There is more general enhancement information for 10.3.5 located here:

Combo Updater: Link

Normal Updater: Link

What Do You Think?

 

Want to Start a Blog Here for Free?

Are you an expert in one subject or another? If your goal is to help others and dispense your hard-earned information back to the community, get involved in our community site today! You can write about anything - no matter the topic. Exceptional candidates will be offered the chance to contribute to (and generate revenue from) the main Lockergnome site. Join us today!

Fun - Apr 24, 2008

Airport Mania: First Flight For Mac

Feedback, Talk - Apr 7, 2008

Is OS X For You?

67 queries / 0.173 seconds.