Risk
3/29/2010
02:56 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

OS X Gets Massive Patch, Microsoft Closes Zero-Day

Apple drops a patch for a staggering 88 vulnerabilities while Microsoft closes a hole in certain versions of Internet Explorer that have been under attack for several weeks.

Apple drops a patch for a staggering 88 vulnerabilities while Microsoft closes a hole in certain versions of Internet Explorer that have been under attack for several weeks.Apple today published Security Update 2010-002 / Mac OS X v10.6.3. The update can be downloaded using the OS X Software Update. If you're a Mac user and it hasn't triggered automatically, I suggest you update right away.

Some of the 88 vulnerabilities make it possible for OS X users to get infected with malware, or have their systems hijacked by viewed an especially crafted files.

A number of critical vulnerabilities include those in AppKit, QuickTime, and Image RAW.

Switching from Cupertino, CA to Redmond, WA - Microsoft said it plans to publish an "out-of-band" patch that fills the Internet Explorer 6 and 7 vulnerability that has been under attack for some time.

According to Microsoft Security Advisory 981374, first published on March 9, targeted attacks were underway at that time.

The flaw doesn't affect Internet Explorer 8 or 7. More information of the patch is available in Microsoft Security Bulletin Advance Notification for March 2010.

This risk from this vulnerability should be quite serious, or the company would have waited to roll this update out on the second Tuesday of April.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-1978
Published: 2015-05-21
Multiple cross-site request forgery (CSRF) vulnerabilities in Simple PHP Agenda 2.2.8 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator via a request to auth/process.php, (2) delete an administrator via a request to auth/admi...

CVE-2015-0741
Published: 2015-05-21
Multiple cross-site request forgery (CSRF) vulnerabilities in Cisco Prime Central for Hosted Collaboration Solution (PC4HCS) 10.6(1) and earlier allow remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCut04596.

CVE-2015-0742
Published: 2015-05-21
The Protocol Independent Multicast (PIM) application in Cisco Adaptive Security Appliance (ASA) Software 9.2(0.0), 9.2(0.104), 9.2(3.1), 9.2(3.4), 9.3(1.105), 9.3(2.100), 9.4(0.115), 100.13(0.21), 100.13(20.3), 100.13(21.9), and 100.14(1.1) does not properly implement multicast-forwarding registrati...

CVE-2015-0746
Published: 2015-05-21
The REST API in Cisco Access Control Server (ACS) 5.5(0.46.2) allows remote attackers to cause a denial of service (API outage) by sending many requests, aka Bug ID CSCut62022.

CVE-2015-0915
Published: 2015-05-21
Cross-site scripting (XSS) vulnerability in RAKUS MailDealer 11.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted attachment filename.

Dark Reading Radio
Archived Dark Reading Radio
Join security and risk expert John Pironti and Dark Reading Editor-in-Chief Tim Wilson for a live online discussion of the sea-changing shift in security strategy and the many ways it is affecting IT and business.