[IS&T Security-FYI] Apple Security Patches - Feb. 16, 2007

Monique Yeaton myeaton at MIT.EDU
Tue Feb 20 09:38:55 EST 2007


To our Apple users:

This Security Alert comes from CERT.org.

Systems Affected

      * Apple Mac OS X version 10.3.x and 10.4.x
      * Apple Mac OS X Server version 10.3.x and 10.4.x
      * Apple iChat

    These vulnerabilities affect both Intel-based and PowerPC-based  
Apple
    systems.


Overview

    Apple has released Security Update 2007-002 to correct multiple
    vulnerabilities affecting Apple Mac OS X, Mac OS X Server, and  
iChat.
    The most serious of these vulnerabilities may allow a remote  
attacker
    to execute arbitrary code. Attackers may take advantage of the less
    serious vulnerabilities to bypass security restrictions or cause a
    denial of service.


I. Description

    Apple Security Update 2007-002 addresses a number of vulnerabilities
    affecting Apple Mac OS X, OS X Server, and iChat. Further details  
are
    available in the related vulnerability notes.

    The vulnerabilities addressed in this update were previously  
disclosed
    as part of the Month of Apple Bugs project.


II. Impact

    The impacts of these vulnerabilities vary. Potential consequences
    include remote execution of arbitrary code or commands, bypass of
    security restrictions, and denial of service.


III. Solution

Install Updates from Apple

    Install Apple Security Update 2007-002. This and other updates are
    available via Apple Update or via Apple Downloads.


IV. References

      * Vulnerability Notes for Apple Security Update 2007-002 -
        <http://www.kb.cert.org/vuls/byid? 
searchview&query=Apple-2007-002>

      * About the security content of Security Update 2007-002 -
        <http://docs.info.apple.com/article.html?artnum=305102>

      * Month of Apple Bugs -
        <http://projects.info-pull.com/moab/index.html>

      * Mac OS X: Updating your software -
        <http://docs.info.apple.com/article.html?artnum=106704>

      * Apple Downloads - <http://www.apple.com/support/downloads/>

Monique







More information about the ist-security-fyi mailing list