Categories: MacSecurityWorkspace

Apple Update Patches 13 Mac Vulnerabilities

Apple has released a security update that fixes a number of issues in several components, including CoreGraphics and Apple Type Services. Several of the vulnerabilities are buffer overflows, and can be exploited to execute arbitrary code.

According to the Apple advisory, the Apple Type Services (ATS) bug can be triggered by viewing or downloading a document containing a malicious embedded font. If exploited, hackers could use it to run code.

Apple said it fixed the issue through improved bounds checking.

A heap buffer overflow due to CoreGraphics’ handling of PDF files can also be exploited by attackers to run arbitrary code, and was likewise addressed with improved bounds checking.

Five of the vulnerabilities affect PHP, and were addressed by updating to PHP 5.3.1. A sixth PHP bug – a buffer overflow in PHP’s libpng library – was swatted by updating libpng within PHP to version 1.4.3. That last issue can be exploited via a malicious PNG image, and does not affect systems prior to Mac OS X v10, according to the advisory.

Other components affected by the update include: CFNetwork, libsecurity, Samba and ClamAV.

Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Share
Published by
Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Recent Posts

OpenAI Hit By Austrian Complaint Over ChatGPT ‘False Data’

Rights group argues ChatGPT tendency to generate false information on individuals violates GDPR data protection…

7 hours ago

EU Designates Apple’s iPad OS As DMA ‘Gatekeeper’

European Commission says Apple's iPadOS is 'gatekeeper' due to large number of businesses 'locked in'…

7 hours ago

Beating the Barbarians in the Cloud

As the cloud continues to be an essential asset for all businesses, developing and maintaining…

8 hours ago

Austria Conference Calls For Controls On ‘Killer Robots’

Internatinal conference in Vienna calls for controls on AI-powered autonomous weapons to ensure humans remain…

8 hours ago

Taiwanese Chip Giant Exits China Mainland

Major Taiwan chip assembly and test firm KYEC to sell Jiangsu subsidiary, exit mainland China…

9 hours ago

Deepfakes: More Than Skin Deep Security

As deepfake technology continues to blur the lines between reality and deception, businesses and individuals…

9 hours ago