Details on Apple's Security Update 2004-08-09

Apple released Security Update 2004-08-09 late yesterday for these system versions: Mac OS X v10.3.4 (Panther), Mac OS X Server v10.3.4 (Panther), Mac OS X v10.2.8 (Jaguar) and Mac OS X Server v10.2.8 (Jaguar). It is included in the Mac OS X 10.3.5 Update noted above.

The update fixes the portable network graphics (PNG) vulnerability we noted last Friday and it is available via the Software Update preference pane or as a standalone updater for 10.2.8 or 10.3.4. The Read Me file states:

Security Update 2004-08-09 delivers a number of security enhancements and is recommended for all Macintosh users. This update includes the following components:

libpng (Portable Network Graphics)

The details are:

libpng (Portable Network Graphics) Fixes CAN-2002-1363, CAN-2004-0421, CAN-2004-0597, CAN-2004-0598, CAN-2004-0599

Impact: Malicious PNG images can cause application crashes and could execute arbitrary code

Description: A number of buffer overflows, null pointer dereferences and integer overflows have been discovered in the reference library for reading and writing PNG images. These vulnerabilities have been corrected in libpng which is used by the CoreGraphics and AppKit frameworks in Mac OS X. After installing this update, applications that use the PNG image format via these frameworks will be protected against these flaws.


Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Security · This month in the archive