Risk
3/29/2010
02:56 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

OS X Gets Massive Patch, Microsoft Closes Zero-Day

Apple drops a patch for a staggering 88 vulnerabilities while Microsoft closes a hole in certain versions of Internet Explorer that have been under attack for several weeks.

Apple drops a patch for a staggering 88 vulnerabilities while Microsoft closes a hole in certain versions of Internet Explorer that have been under attack for several weeks.Apple today published Security Update 2010-002 / Mac OS X v10.6.3. The update can be downloaded using the OS X Software Update. If you're a Mac user and it hasn't triggered automatically, I suggest you update right away.

Some of the 88 vulnerabilities make it possible for OS X users to get infected with malware, or have their systems hijacked by viewed an especially crafted files.

A number of critical vulnerabilities include those in AppKit, QuickTime, and Image RAW.

Switching from Cupertino, CA to Redmond, WA - Microsoft said it plans to publish an "out-of-band" patch that fills the Internet Explorer 6 and 7 vulnerability that has been under attack for some time.

According to Microsoft Security Advisory 981374, first published on March 9, targeted attacks were underway at that time.

The flaw doesn't affect Internet Explorer 8 or 7. More information of the patch is available in Microsoft Security Bulletin Advance Notification for March 2010.

This risk from this vulnerability should be quite serious, or the company would have waited to roll this update out on the second Tuesday of April.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Five Emerging Security Threats - And What You Can Learn From Them
At Black Hat USA, researchers unveiled some nasty vulnerabilities. Is your organization ready?
Flash Poll
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
Join Dark Reading community editor Marilyn Cohodas and her guest, David Shearer, (ISC)2 Chief Executive Officer, as they discuss issues that keep IT security professionals up at night, including results from the recent 2016 Black Hat Attendee Survey.