Apple Released Security Update 2004-09-16
Security Update 2004-09-16 delivers a number of security enhancements and is recommended for all Macintosh users. This update includes the following component:
iChat [Updated InstantMessage Framework from v187 to v193--ed.]
For detailed information on this Update, please visit this website: http://www.info.apple.com/kbnum/n61798
The update fixes this vulnerability:
CVE-ID: CAN-2004-0873
Impact: Remote iChat participants can send "links" that can start
local programs if clicked.
Description: A remote iChat participant can send a "link" that
references a program on the local system. If the "link" is activated
by clicking on it, and the "link" points to a local program, then the
program will run. iChat has been modified so that "links" of this
type will open a Finder window that displays the program instead of
running it. Credit to <aaron@vtty.com> for reporting this issue.
We downloaded the update and installed it on several Macs: G5's, G4 Cube and PowerBook G4's, with no apparent problems. [Dana Baggett]
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?