Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Apple releases Security Update 2010-003 for OS X Leopard and Snow Leopard
Apple Inc. ^ | 04/14/2010

Posted on 04/15/2010 8:04:06 AM PDT by Swordmaker

About the content of Security Update 2010-003
Last Modified: April 14, 2010
Article: HT4131

Products Affected
Product Security, Mac OS X Server 10.5, Mac OS X 10.5, Mac OS X 10.6, Mac OS X Server 10.6

Security Update 2010-003

ATS

CVE-ID: CVE-2010-1120
Available for: Mac OS X v10.5.8, Mac OS X Server v10.5.8, Mac OS X v10.6.3, Mac OS X Server v10.6.3

Impact: Viewing or downloading a document containing a maliciously crafted embedded font may lead to arbitrary code execution.

Description: An unchecked index issue exists in Apple Type Services' handling of embedded fonts. Viewing or downloading a document containing a maliciously crafted embedded font may lead to arbitrary code execution. This issue is addressed through improved index checking. Credit to Charlie Miller working with TippingPoint's Zero Day Initiative for reporting this issue.


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: internet; maccult; macvirus; viruses
This security update closes the vulnerability revealed and demonstrated by Charlie Miller when he won the latest CanSec West Tipping Point Security Challenge contest in which OS X, Windows 7, and Linux all fell to hackers in short order.

As last year's winner,and defending champion, Miller received the first time slot to make his hacking attempt and again chose to attack OS X. Two minutes into his assault with an attack that took three weeks to find and prepare with the assistence of his two ex-NSA computer-security employees, OS X fell to this now closed, previously un-revealed vulnerability, securing this year's win, $10,000, and a MacBook Pro for Miller.

Windows 7 and Linux also fell under the first assaults aimed at their defenses by the expert hackers at CanSec West. All attacks were pre-prepared this year, unlike previous years' contests, where Miller was the only one who came with a pre-researched, prepared exploit.

1 posted on 04/15/2010 8:04:06 AM PDT by Swordmaker
[ Post Reply | Private Reply | View Replies]

To: Action-America; acoulterfan; AFreeBird; Airwinger; Aliska; altair; aristotleman; af_vet_rr; ...
It's time for all security conscious Mac owners with Leopard and Snow Leopard to click on the black Apple menu item and select "Software update..." PING!

Apple has release the patch to close the security vulnerability disclosed and exploited by Charlie Miller when he won this year's CanSec West computer security Blackhat hacking contest earlier this month by hacking into a MacBook Pro and winning the laptop and $10,000!


Mac Security Ping!

If you want on or off the Mac Ping List, Freepmail me.

2 posted on 04/15/2010 8:24:17 AM PDT by Swordmaker (Remember, the proper pronunciation of IE isAAAAIIIIIEEEEEEE!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

In before the “I thought Macs were hacker proof” posts.


3 posted on 04/15/2010 9:18:29 AM PDT by Mr. Blonde (You ever thought about being weird for a living?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Done. Thanks...


4 posted on 04/15/2010 9:47:49 AM PDT by tubebender (Don 't pick a fight with an old man.  If he is too old to fight, he'll just shoot you...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Thanks - seems to have been a lot of Apple patches lately - on the OS and apps.


5 posted on 04/15/2010 9:49:43 AM PDT by Salo
[ Post Reply | Private Reply | To 2 | View Replies]

To: Swordmaker
Thanks Swordmaker, for the
Image Hosted by ImageShack.us !

6 posted on 04/15/2010 10:11:34 AM PDT by vox_freedom (America is being tested as never before in its history. May God help us.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Mr. Blonde
I was just thinkin' the same.

Some times you have to hunt them down.



11 trolls. Click for the answer.

7 posted on 04/15/2010 10:38:36 AM PDT by Leonard210 (Tagline? We don't need no stinkin' tagline.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Swordmaker

Got it. Thanks


8 posted on 04/15/2010 11:27:28 AM PDT by Vinnie (You're Nobody 'Til Somebody Jihads You)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Salo
Thanks - seems to have been a lot of Apple patches lately - on the OS and apps.

Nope, just three batches of security updates this year for THREE versions of the Operating System. That's not too bad.

And Apple includes all updates for UNIX and Apps...

9 posted on 04/15/2010 3:08:36 PM PDT by Swordmaker (Remember, the proper pronunciation of IE isAAAAIIIIIEEEEEEE!)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Swordmaker

Thanks for the ping, Swordmaker. I wouldn’t hve known till Saturday, when my Mac does it’s weekly software update check.

You keep me ahead of the curve!


10 posted on 04/15/2010 6:42:32 PM PDT by jacquej
[ Post Reply | Private Reply | To 2 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson