On TV.com: Confession: I Like THE BIG BANG THEORY
BNET Business Network:
BNET
TechRepublic
ZDNet

July 31st, 2007

Apple monster update fixes iPhone, Safari, Mac OS X flaws

Posted by Ryan Naraine @ 8:59 pm

Categories: Apple, Black Hat, Botnets, Browsers, Data theft, Digital rights management, Google, Hackers, McAfee, Metasploit, Mozilla, Open source, Patch Watch, Pen testing, Responsible disclosure, Spyware and Adware, Viruses and Worms, Vulnerability research, Windows Vista, Zero-day attacks

Tags: Apple iPhone, Apple Mac OS, Apple Macintosh, Apple Inc., Apple Mac OS X, Flaw, Ryan Naraine

Apple monster update fixes iPhone, Safari, Mac OS X flawsLAS VEGAS — Apple has issued a monster update with patches for about 50 security vulnerabilities affecting iPhone, Safari and Mac OS X users.

In a race against the clock, the company rushed out iPhone v1.0 with fixes for four different vulnerabilities that could allow hackers to take full control of the device. The fix comes 24 hours ahead of the expected full disclosure of one of the iPhone vulnerabilities at the Black Hat security conference here.

Security researcher Charlie Miller, who found what is believed to be the first remotely exploitable iPhone bug, told me by e-mail earlier that he was giving his iPhone takeover demo whether or not Apple released a patch.

Apple’s advisory, Miller is credited with finding and reporting one of the issues — heap buffer overflows in the Perl Compatible Regular Expressions (PCRE) library used by the JavaScript engine in Safari. The iPhone update, which is only available via iTunes, also fixes three other flaws in Safari, WebCore and WebKit.

Apple also released a separate advisory to highlight the browser fixes available for Safari. The bugs could cause code execution attacks on Mac OS X, Windows XP and Windows Vista systems.

A third advisory from Cupertino (Security Update 2007-007) patches a total of 45 vulnerabilities in a wide range of Mac OS X components.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 82 Talkback(s)
So, what do you do at the office?
I have consistantly heard this judgement from a wide number of noisy but uninformed users. So I consistantly ask the question "What do you do at the office?"

E-mail? Ok. There are 3rd party Exc... (Read the rest)
Posted by: jjmcdonald7911@... Posted on: 07/25/08 You are currently: a Guest | | Terms of Use
Good lord Ryan , do you ever sleep ? ROTFLMAO  MythBuster | 07/31/07
Have you tried  Stuka | 08/01/07
Ah.  xuniL_z | 08/01/07
*yawn* (NT)  Stuka | 08/01/07
I thought that Jobs guy looked a bit shady  dougscrm@... | 08/01/07
Is this parody?  buddhistMonkey | 08/01/07
Reality hits home and some cant see it  Cayble | 08/04/07
Way cool.......  Laff | 08/01/07
Apple the new patch monster?  Scrat | 08/01/07
Actually "patches" don't bother me or at least come  Laff | 08/01/07
By the way... (Leopard news)  systemx | 08/01/07
what Apple bugs?  asdf44444 | 08/01/07
not as hilarious as...  pir8matt | 08/01/07
Jobs said they were a Software company  JABBER_WOLF | 08/01/07
re: what Apple bugs?  Macathome | 08/01/07
While it was out-of-line, I think he's referring to  fr0thy2. | 08/01/07
Exactly.  Cayble | 08/04/07
Less bugs...  levinson | 08/01/07
Gun Jumping  DannyO_0x98 | 08/01/07
C'mon now, let's be professional about this  SteveMak | 08/01/07
Sensationalized?  lmenningen | 08/01/07
The very same sentence had the words OSX "FLAWS"  Laff | 08/01/07
Update size  levinson | 08/01/07
Was hoping for the SMS fix.  rand@... | 08/01/07
Fix what? It works as designed  NonZealot | 08/01/07
Fashion over function? You gotta be kidding me...  rand@... | 08/01/07
You're feeding the troll. Just ignore him. [nt]  olePigeon | 08/01/07
Greater possibilities  terry@... | 08/01/07
RE: Greater possibilities  joe6pack_z | 08/01/07
Can't Apple code anything right?  NonZealot | 08/01/07
mac  droidhorse | 08/01/07
Just to play devil's advocate here  laura.b | 08/01/07
Just to play Angel's Advocate  DannyO_0x98 | 08/01/07
You're not being much of an advocate  zkiwi | 08/01/07
Yup, all about the marketshare  NonZealot | 08/01/07
And yet...  zkiwi | 08/01/07
whatever  xuniL_z | 08/01/07
Message has been deleted.  zkiwi | 08/01/07
So...  zkiwi | 08/02/07
why?  xuniL_z | 08/02/07
Burn off Microsoft  levinson | 08/01/07
You're right...I just forgot because it sucks so badly.  laura.b | 08/03/07
Looking at iWork,  msalzberg | 08/04/07
So, what do you do at the office?  jjmcdonald7911@... | 07/25/08
Excuse, me, "Bum one off of Microsoft"?  jjmcdonald7911@... | 07/25/08
How do you know?  NonZealot | 08/01/07
And how do you know...  zkiwi | 08/01/07
Beautiful coding  frgough | 08/01/07
Hehe, it can't be THAT beautiful!!  NonZealot | 08/01/07
take churchill's advice  frgough | 08/01/07
You have to remember..  msalzberg | 08/01/07
Of everyone here..  msalzberg | 08/02/07
Actually, that's why there are many patches  John Zern | 08/01/07
Welcome back from vacation  MacCanuck | 08/01/07
You've seen OSX's source code?  NonZealot | 08/01/07
Well  zkiwi | 08/01/07
I'll take that as a no.  NonZealot | 08/01/07
No to your "no"  MarcB_z | 08/01/07
No more than you've seen Windows'  MacCanuck | 08/02/07
I get it, Zealot...  msalzberg | 08/01/07
Hey, you DO get it!!  NonZealot | 08/01/07
Do you even read what you post?  msalzberg | 08/01/07
Secure by design?  zkiwi | 08/01/07
Actually, the Zealot has actually  msalzberg | 08/01/07
I know, you have to wonder  xuniL_z | 08/01/07
talk about  xuniL_z | 08/01/07
Whee!  zkiwi | 08/01/07
I'm glad you agree.  xuniL_z | 08/02/07
I don't agree with you  zkiwi | 08/02/07
So  xuniL_z | 08/02/07
I can see you are not a very efficient coder....  xuniL_z | 08/03/07
I know but why am I left out?  xuniL_z | 08/02/07
I'm in the same boat..  msalzberg | 08/02/07
I know what the problem is  NonZealot | 08/02/07
Ha! No.  Laff | 08/02/07
Ha. that was a flashback  xuniL_z | 08/02/07
I've just figured it out!!!!  msalzberg | 08/01/07
Derrr, what??  zeusx64@... | 08/01/07
Ryan, you're a such a DOUCHE! What will you call Vista SP1?  usc1801 | 08/01/07
Nonzealot has a busy day...  Non-Zealand | 08/01/07
Message has been deleted.  Kobashrer | 08/01/07
Did you notice it says "Flaws?"  JoeBob_z | 08/03/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here