Apple Released Security Update 2004-09-16

late yesterday. It is available for Mac OS X 10.3.5, 10.3.4 and 10.2.8, client and server editions, via the Software Update preference pane or from this Apple web page. According to the Read Me file,

Security Update 2004-09-16 delivers a number of security enhancements and is recommended for all Macintosh users. This update includes the following component:

iChat [Updated InstantMessage Framework from v187 to v193--ed.]


For detailed information on this Update, please visit this website: http://www.info.apple.com/kbnum/n61798

The update fixes this vulnerability:

CVE-ID: CAN-2004-0873
Impact: Remote iChat participants can send "links" that can start
local programs if clicked.
Description: A remote iChat participant can send a "link" that
references a program on the local system. If the "link" is activated
by clicking on it, and the "link" points to a local program, then the
program will run. iChat has been modified so that "links" of this
type will open a Finder window that displays the program instead of
running it. Credit to <aaron@vtty.com> for reporting this issue.

We downloaded the update and installed it on several Macs: G5's, G4 Cube and PowerBook G4's, with no apparent problems. [Dana Baggett]


Saw something? Send a tip or a correction

The archive ran on reader tips. What did you see, where, and do you want the credit? Something wrong on this page? Say so and it gets fixed.

Read by the editor. You get a copy by email. Never published without your say.

More in Security · This month in the archive