Details on Apple Security Update 2005-004

Security Update 2005-004 is now available via the System Preferences Software Update pane, if iSync 1.5 is installed, and as a standalone updater from this Apple Web page. It delivers the following security enhancement:

iSync
Available for: iSync 1.5
CVE-ID: CAN-2005-0193
Impact: A buffer overflow in iSync could lead to local privilege escalation
Description: The iSync helper tool mRouter contains a buffer overflow vulnerability. This could result in the execution of arbitrary commands as root by local system users. Security Update 2005-004 fixes this problem by providing a patched version of mRouter. iSync 1.4 is also affected by this vulnerability, and customers are encouraged to update to the freely available iSync 1.5 version, then apply Security Update 2005-004. Credit to Braden Thomas for reporting this issue.

We downloaded and installed the update on several Macs and PowerBooks with no problems. It did not change the version (1.5) or Build number (139) [Bill Fox & Dana Baggett]



Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Security · This month in the archive