On TechRepublic: Five super-secret features in Windows 7
BNET Business Network:
BNET
TechRepublic
ZDNet

July 31st, 2008

Apple finally ships DNS flaw fix, patches 16 other Mac OS X holes

Posted by Ryan Naraine @ 8:21 pm

Categories: Adobe, Apple, Arbitrary Code Execution, Botnets, Browsers, Data theft, Denial of Service (DoS), Exploit code, Kernel-level Exploits, Open source, Passwords, Patch Watch, Pen testing, Privacy, Responsible disclosure, Viruses and Worms, Vulnerability research, Web Applications

Tags: Apple Macintosh, DNS, Patch Management, Apple Inc., Issue, Arbitrary Code Execution, Flaw, Application Termination, Apple Mac OS X, Apple Mac OS

Apple finally ships DNS flaw fix, patches 16 other Mac OS X holes [ UPDATE: nCircle Andrew Storms reports that the DNS client on the OSX 10.4.11 distribution still has not been patched.  ]

Apple has shipped a Mac OS X security update with patches for at least 17 documented vulnerabilities, including a fix for the serious DNS cache poisoning vulnerability reported by hacker Dan Kaminsky.

With Security Update 2008-005, Apple plugs holes that could lead to privilege escalation, denial-of-service, information disclosure and arbitrary code execution attacks.

The update affects Mac OS X Server 10.4, Mac OS X 10.4.11, Mac OS X Server 10.5, and Mac OS X 10.5.4.

[ Microsoft joins ‘patch DNS now’ chant; Apple patch missing ]

Vulnerability details below the fold:

CVE-2008-1447 - BIND:  A weakness in the DNS protocol may allow remote attackers to perform DNS cache poisoning attacks. As a result, systems that rely on the BIND server for DNS may receive forged information. This update addresses the issue by implementing source port randomization to improve resilience against cache poisoning attacks. For Mac OS X v10.4.11 systems, BIND is updated to version 9.3.5-P1. For Mac OS X v10.5.4 systems, BIND is updated to version 9.4.2-P1.

CVE-2008-2320 - CarbonCore: A stack buffer overflow exists in the handling of long filenames. Processing long filenames may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue through improved bounds checking.

CVE-2008-2830 - Open Scripting Architecture: A design issue exists in the Open Scripting Architecture libraries when determining whether to load scripting addition plugins into applications running with elevated privileges. Sending scripting addition commands to a privileged application may allow the execution of arbitrary code with those privileges. This update addresses the issue by not loading scripting addition plugins into applications running with system privileges.

CVE-2008-2321 - CoreGraphics:  CoreGraphics contains memory corruption issues in the processing of arguments. Passing untrusted input to CoreGraphics via an application, such as a web browser, may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue through improved bounds checking.

 CVE-2008-2322 - CoreGraphics: An integer overflow in the handling of PDF files may result in a heap buffer overflow. Viewing a maliciously crafted PDF file may lead to an unexpected application termination or arbitrary code execution.

 CVE-2008-2323 - Data Detectors Engine:  Viewing maliciously crafted content in an application that uses Data Detectors may lead to a denial of service, but not arbitrary code execution. This issue does not affect systems prior to Mac OS X v10.5.

CVE-2008-2324 - Disk Utility: The “Repair Permissions” tool in Disk Utility makes /usr/bin/emacs setuid. After the Repair Permissions tool has been run, a local user may use emacs to run commands with system privileges. This update addresses the issue by correcting the permissions applied to emacs in the Repair Permissions tool.

CVE-2008-2952 - OpenLDAP: An issue exists in OpenLDAP’s ASN.1 BER decoding. Processing a maliciously crafted LDAP message may trigger an assertion and lead to an unexpected application termination of the OpenLDAP daemon, slapd. This update addresses the issue by performing additional validation of LDAP messages.

CVE-2007-5135 - OpenSSL: A range checking issue exists in the SSL_get_shared_ciphers() utility function within OpenSSL. In an application using this function, processing maliciously crafted packets may lead to an unexpected application termination or arbitrary code execution.

CVE-2008-2051, CVE-2008-2050, CVE-2007-4850, CVE-2008-0599, CVE-2008-0674: PHP is updated to version 5.2.6 to address multiple vulnerabilities, the most serious of which may lead to arbitrary code execution. Further information is available via the PHP website at http://www.php.net/ PHP version 5.2.x is only provided with Mac OS X v10.5 systems.

CVE-2008-2325 - QuickLook: Multiple memory corruption issues exist in QuickLook’s handling of Microsoft Office files. Downloading a maliciously crafted Microsoft Office file may lead to an unexpected application termination or arbitrary code execution.

CVE-2007-6199, CVE-2007-6200 - rsync: Path validation issues exist in rsync’s handling of symbolic links when running in daemon mode. Placing symbolic links in an rsync module may allow files outside of the module root to be accessed or overwritten. Further information on the patches applied is available via the rsync web site at http://rsync.samba.org.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 53 Talkback(s)
Um NO....
OSX has NEVER and I mean NEVER under any setting that I
have used or was pre-installed by Apple not only once but
constantly over a few minutes span tried to force me to
restart. Even aft... (Read the rest)
Posted by: James Quinn Posted on: 08/04/08 You are currently: a Guest | | Terms of Use
Scary combination of arbitrary code execution and privilege escalation!!!  NonZealot | 07/31/08
Always good to see you bringing your humour here to ZDNet.  Arm A. Geddon | 07/31/08
Don't worry  frabjous | 08/01/08
Btw, I'm really scared...  Arm A. Geddon | 07/31/08
are you one of those unaware fanboys?  zupobaloop | 08/01/08
Do you have hard numbers to prove your assertion?  rdawson@... | 08/01/08
i thought you read zdnet  zupobaloop | 08/01/08
I think I saw that and there were many who  James Quinn | 08/01/08
Then go to the authoritative site.  xuniL_z | 08/01/08
Well.........  James Quinn | 08/04/08
So how many Mac users were effected?  James Quinn | 08/01/08
like it matters  zupobaloop | 08/01/08
In the whole of human history do you have any  James Quinn | 08/01/08
wrong wrong wrong  zupobaloop | 08/01/08
DO you read what I wrote?  James Quinn | 08/04/08
You strike me as the "Chicken Little" type...  James Quinn | 08/01/08
Would that OS be Linux?  mahalotmm | 08/01/08
No, he said secure OS (NT)  Loverock Davidson | 08/01/08
So, that'd leave out...  zkiwi | 08/04/08
unless one is looking...  xuniL_z | 08/04/08
Shut up  zkiwi | 08/04/08
There is a difference between "best" and most used  James Quinn | 08/04/08
RE: Apple finally ships DNS flaw fix  Tim99 | 07/31/08
Truncated Feedback system  Tim99 | 07/31/08
That Story is Bunk  mikefarinha | 08/01/08
Read again..  vmaatta | 08/01/08
RE: Apple finally ships DNS flaw fix, patches 16 other Mac OS X holes  jamalystic | 08/01/08
RE: Apple finally ships DNS flaw fix, patches 16 other Mac OS X holes  jamalystic | 08/01/08
are you kidding?  zupobaloop | 08/01/08
And Windows marketing is different how?  rdawson@... | 08/01/08
marketing...  zupobaloop | 08/01/08
I have two PC's and a Mac and...  marksashton | 08/01/08
Again with the personal unverifiable tales...  James Quinn | 08/01/08
Because...  socialism=nowhere | 08/01/08
Yeah it's just annoying to have an OS set up out  James Quinn | 08/01/08
lol out grown the phase?  zupobaloop | 08/01/08
Much older than you seem to think...  James Quinn | 08/01/08
Yeah Laff we get it...  joethemacfan | 08/01/08
Perhaps but if the manufacturer does not server  James Quinn | 08/01/08
It's ironic you say that.  xuniL_z | 08/04/08
Um NO....  James Quinn | 08/04/08
Way too many patches  jessedorland@... | 08/01/08
Microsoft does that on Windows Update  marksashton | 08/04/08
How much more proof...  wcb42ad | 08/01/08
Tru Dat.....  James Quinn | 08/01/08
you said it  zupobaloop | 08/01/08
Did Apple forget to patch something?  Ryan NaraineZDNet Moderator | 08/01/08
10.4.11 came out a while back......  James Quinn | 08/01/08
Oops...I see what you were saying now.  James Quinn | 08/01/08
I think they are talking about security update 2008-005  phatkat | 08/01/08
Independent verification of this?  phatkat | 08/01/08
RE: Apple finally ships DNS flaw fix, patches 16 other Mac OS X holes  jessedorland@... | 08/01/08
Apple = MS + worse  T1Oracle | 08/01/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline