Apple Released Security Update 2004-09-16

late yesterday. It is available for Mac OS X 10.3.5, 10.3.4 and 10.2.8, client and server editions, via the Software Update preference pane or from this Apple web page. According to the Read Me file,

Security Update 2004-09-16 delivers a number of security enhancements and is recommended for all Macintosh users. This update includes the following component:

iChat [Updated InstantMessage Framework from v187 to v193--ed.]


For detailed information on this Update, please visit this website: http://www.info.apple.com/kbnum/n61798

The update fixes this vulnerability:

CVE-ID: CAN-2004-0873
Impact: Remote iChat participants can send "links" that can start
local programs if clicked.
Description: A remote iChat participant can send a "link" that
references a program on the local system. If the "link" is activated
by clicking on it, and the "link" points to a local program, then the
program will run. iChat has been modified so that "links" of this
type will open a Finder window that displays the program instead of
running it. Credit to <aaron@vtty.com> for reporting this issue.

We downloaded the update and installed it on several Macs: G5's, G4 Cube and PowerBook G4's, with no apparent problems. [Dana Baggett]


Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Security · This month in the archive