Apple released a king-sized security update for Mac OS X on Thursday, a separate fix for its just-released Snow Leopard, and an update to the iPhone operating system. Some of the updates fix problems, but others seem to cause new ones.
Thursday’s updates fix 33 vulnerabilities in the Mac OS X Leopard operating system involving third-party applications such as Adobe Flash, Samba, MySQL and PHP. The Leopard update also addresses potential security vulnerabilities in Alias Manager, CarbonCore, CUPS, ColorSynch, ImageIO, Wiki Server, CoreGraphics and Launch Services.
Apple has a history of being haunted by vulnerabilities in third-party products. The key issues in the latest advisories are buffer overflows, integer overflows, and memory corruption.
Third-Party Headaches
Apple would serve itself well to figure out how to optimize the bundling of third-party applications and create some space between third-party apps and the Mac OS, according to Andrew Storms, director of security for nCircle.
“Apple really needs to learn how to close the time loophole on third-party products. Thursday’s PHP update was released into the community back in June,” Storms said. “Unfortunately for Apple, they needed to create an entirely new point release for their operating system in order to push out a patch to a third-party product.”
With the Leopard update, Apple is also addressing basic enterprise security needs. Two items of particular interest involve circumventing security if an attacker has access to a physical device.
“One of these items is the ability to circumvent the administrator set screen lockout time duration, the second lets an attacker recover data from the device even when locked by using the Apple recovery tool,” Storms said. “These are both basic handheld-device security mechanisms that Apple needs to nail in order to be trusted in the enterprise.”
Snow Leopard Fixes, iPhone Problems
Even though Apple previously released patches around SMS vulnerabilities based on…