While the Mac-using world awaits the fall arrival of Snow Leopard, Apple is doing some cleanup work on the current version of its Macintosh operating system. On Wednesday, Apple patched 18 vulnerabilities in Mac OS X.
Despite the fact that this is Apple’s lightest update this year, six of the flaws are rated critical. That means the bugs could open the door to attackers to hijack a computer by tricking victims into viewing malicious image files on the Internet.
Apple distributed Security Update 2009-003 with the Mac OS X 10.5.8 update for both the Leopard and Tiger operating systems to fix vulnerabilities in Dock, Colorsync and the MobileMe storage service. But the six critical vulnerabilities are drawing the attention of analysts.
Prevalent PNG Issues
Among the nearly 20 bugs fixed, the most worrisome and prevalent issues affect various image-handling scenarios, according to Andrew Storms, director of security operations at nCircle.
“In one case, simply opening a PNG file can lead to a remote attacker gaining control over a Mac. Given the pervasiveness of PNG files on the Internet, in e-mail, and across Web sites, this bug is of particular concern,” Storms said.
A vulnerability in the Mac OS X CFNetwork could lead to a maliciously crafted Web site that spoofs the real host. Here’s how it works: When the Safari browser reaches a Web site via a 302 redirection and a certificate warning is displayed, the warning contains the original Web-site URL instead of the current, redirected Web-site URL. This could allow a maliciously crafted Web site to control the displayed Web-site URL in a certificate warning to give users a false sense of security.
Third-Party Flaws
Another image vulnerability exists in the way the operating system handles Canon RAW images. Apple said viewing a maliciously crafted Canon RAW image may lead to an unexpected application termination…