Online Media - Publish.com
Publish.com Ziff-Davis Enterprise  
SEARCH · ONLINE MEDIA · MOBILE · WEB DESIGN · GRAPHICS TOOLS · PRINTING · PHOTO · TIPS · OPINIONS
Home arrow Online Media arrow Mac OS X Patch Misses Mark, Causes Hiccups
Mac OS X Patch Misses Mark, Causes Hiccups
By Ryan Naraine

Rate This Article:
Add This Article To:
An independent security researcher reports that Apple's most recent security update fails to address well-known vulnerabilities. Also, users are reporting boot-up hiccups after the mega patch is installed.

Apple Computer's latest Mac OS X security update misses several dangerous vulnerabilities and is causing system hangs and boot-up problems for some users, according to information reaching eWEEK.

Less than a week after Apple shipped a mega-update with fixes for a whopping 43 Mac OS X and QuickTime vulnerabilities, independent researcher Tom Ferris said that multiple Safari browser flaws remain unpatched.

Ferris, who has become a bit of a gadfly for Apple, reported the Safari vulnerabilities to Apple on April 19, but after testing the Security Update 2006-003, he told eWEEK the issues have not yet been addressed.

Ferris, who goes by the online moniker of "badpack3t," said the Safari bugs causes the application to crash and may allow a malicious attacker to execute arbitrary code.

On his Security-Protocols.com Web site, Ferris has released technical information on the flaws alongside proof-of-concept code to reproduce the browser crashes.

Back in April, Ferris also flagged a heap overflow vulnerability when specially crafted ".bmp" are processed and decompressed.

Although the Mac OS X update promised a fix for that bug, Ferris insists the underlying issue has not been addressed.

"[The update] does prevent the crash when opening [my] original proof-of-concept file. But after slightly modifying that file, I was able to trigger the same issue with the latest security update installed," Ferris said.

Ferris, who uses fuzzing techniques to identify application bugs, also plans to report several new ".tiff" flaws to Apple's security team.

As per policy, Apple does not comment on potential security vulnerabilities in its products until a fix is available.

Meanwhile, Mac OS X users are reporting post-patch hiccups that range from system hangs and boot-up problems.

In an e-mail message sent to eWEEK, Mac user Stephen Bigelis said the latest security update will hang the computer upon boot for any MacBook Pro user running Adobe Vs Cue software.

"The Adobe software must be removed from the Library->Startupitems Folder in safe mode to get the computer to boot normal," Bigelis added.

On Apple's support forum, there are several threads discussing the boot-up problems.

At the a MacFixIt troubleshooting site, users are also reporting problems with UnRarX and Symantec's LiveUpdate when the security patch is installed.


Discuss Mac OS X Patch Misses Mark, Causes Hiccups
 
>>> Be the FIRST to comment on this article!
 

 
 
>>> More Online Media Articles          >>> More By Ryan Naraine
 


Buyer's Guide
Explore hundreds of products in our Publish.com Buyer's Guide.
Web design
Content management
Graphics Software
Streaming Media
Video
Digital photography
Stock photography
Web development
View all >

ADVERTISEMENT


FREE ZIFF DAVIS ENTERPRISE ESEMINARS AT ESEMINARSLIVE.COM
  • Dec 10, 4 p.m. ET
    Eliminate the Drawbacks of Traditional Backup/Replication for Linux
    with Michael Krieger. Sponsored by InMage
  • Dec 11, 1 p.m. ET
    Data Modeling and Metadata Management with PowerDesigner
    with Joel Shore. Sponsored by Sybase
  • Dec 12, 12 p.m. ET
    Closing the IT Business Gap: Monitoring the End-User Experience
    with Michael Krieger. Sponsored by Compuware
  • Dec 12, 2 p.m. ET
    Enabling IT Consolidation
    with Michael Krieger. Sponsored by Riverbed & VMWare
  • VTS
    Join us on Dec. 19 for Discovering Value in Stored Data & Reducing Business Risk. Join this interactive day-long event to learn how your enterprise can cost-effectively manage stored data while keeping it secure, compliant and accessible. Disorganized storage can prevent your enterprise from extracting the maximum value from information assets. Learn how to organize enterprise data so vital information assets can help your business thrive. Explore policies, strategies and tactics from creation through deletion. Attend live or on-demand with complimentary registration!
    FEATURED CONTENT
    IT LINK DISCUSSION - MIGRATION
    A Windows Vista® migration introduces new and unique challenges to any IT organization. It's important to understand early on whether your systems, hardware, applications and end users are ready for the transition.
    Join the discussion today!



    .NAME Charging For Whois
    Whois has always been a free service, but the .NAME registry is trying to change that.
    Read More >>

    Sponsored by Ziff Davis Enterprise Group

    NEW FROM ZIFF DAVIS ENTERPRISE


    Delivering the latest technology news & reviews straight to your handheld device

    Now you can get the latest technology news & reviews from the trusted editors of eWEEK.com on your handheld device
    mobile.eWEEK.com

     


    RSS 2.0 Feed


    internet
    rss graphic Publish.com
    rss graphic Google Watch

    Video Interviews


    streaming video
    Designing Apps for Usability
    DevSource interviews usability pundit Dr. Jakob Nielsen on everything from the proper attitude for programmers to the importance of prototyping in design to the reasons why PDF, Flash and local search engines can hurt more than they help.
    ADVERTISEMENT