Hands-On Report--Apple Security Update 2005-007 for Mac OS X 10.4.2 and 10.3.9
From the 10.4.2 Client Read Me file,
Security Update 2005-007 delivers a number of security enhancements and is recommended for all Macintosh users. This update includes the following components:
AppKit
BlueTooth
CoreFoundation
cups
Directory Services
HIToolBox
Kerberos
loginwindow
OpenSSL
QuartzComposerScreenSaver
Security Interface
Safari
X11
zlib
From the 10.4.2 Server Read Me file,
Security Update 2005-007 delivers a number of security enhancements and is recommended for all Macintosh users.
This update includes the following components:
apache2
AppKit
blojsom
BlueTooth
CoreFoundation
cups
Directory Services
HIToolBox
Kerberos
loginwindow
OpenSSL
QuartzComposerScreenSaver
Security Interface
servermgrd
servermgr_ipfilter
SquirrelMail
Safari
X11
zlib
Here is a selected listing of the details:
AppKit
CVE-ID: CAN-2005-2501Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.2, Mac OS X Server v10.4.2
Impact: Opening a malicious, rich text file could lead to arbitrary code execution.
Description: A buffer overflow in the handling of maliciously crafted rich text files could lead to arbitrary code execution. This update prevents the buffer overflow from occuring.
AppKit
CVE-ID: CAN-2005-2502Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.2, Mac OS X Server v10.4.2
Impact: Opening a maliciously crafted Microsoft Word .doc file could result in arbitrary code execution.
Description: A buffer overflow in AppKit that is responsible for reading Word documents could allow arbitrary code execution. Only applications such as TextEdit that use AppKit to open Word documents are vulnerable. Microsoft Word for Mac OS X is not vulnerable. This update prevents the buffer overflow.
Bluetooth
CVE-ID: CAN-2005-2504Available for: Mac OS X v10.4.2, Mac OS X Server v10.4.2
Impact: The System Profiler information about whether or not a Bluetooth device requires authentication is misleading.
Description: Selecting "Require pairing for security" in Bluetooth preferences correctly sets the device to require authentication, but in System Profiler the device is labeled with "Requires Authentication: No." This update changes System Profiler to accurately reflect the Bluetooth security settings. This issue does not affect systems prior to Mac OS X 10.4. Credit to John M. Glenn of San Francisco for reporting this issue.
CUPS
CVE-ID: CAN-2005-2525, CAN-2005-2526Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.2, Mac OS X Server v10.4.2
Impact: The CUPS printing service will not print unless it is restarted.
Description: When handling multiple, simultaneous, print jobs, the CUPS printing service can stop printing because it incorrectly tracks open file descriptors. In addition, if CUPS receives a partial IPP request and a client terminates the connection, the printing service will then consume all available CPUs. If the service is restarted, then printing will resume. This update corrects the handling of multiple, simultaneous print jobs and partial requests.
HItoolbox
CVE-ID: CAN-2005-2513Available for: Mac OS X v10.4.2, Mac OS X Server v10.4.2
Impact: VoiceOver may read content from secure input fields.
Description: Under certain circumstances, secure input fields may be read by VoiceOver services. This update stops VoiceOver from exposing the content of these fields. This issue does not affect systems prior to Mac OS X v10.4.
loginwindow
CVE-ID: CAN-2005-2509Available for: Mac OS X v10.4.2, Mac OS X Server v10.4.2
Impact: A user can gain access to other logged-in accounts if Fast User Switching is enabled.
Description: An error in the handling of Fast User Switching can allow a local user who knows the password for two accounts to log into a third account without knowing the password. This update corrects the authentication error. This issue does not affect systems prior to Mac OS X 10.4. Credit to Sam McCandlish for reporting this issue.
CVE-ID: CAN-2005-2512Available for: Mac OS X v10.4.2, Mac OS X Server v10.4.2
Impact: Loss of privacy due to Mail loading remote images in HTML emails.
Description: When Mail.app is used to print or forward an HTML message, it will attempt to load remote images even if a user's preferences disallow it. As this network traffic is not expected, it may be considered a privacy leak. This update addresses the issue by having Mail.app only load remote images in HTML messages when the preferences allow it. This issue does not affect systems prior to Mac OS X v10.4. Credit to Brad Miller of CynicalPeak and John Pell of Foreseeable Solutions for reporting this issue.
For the full detailed information on this update, see this Apple Web page.
We downloaded Security Update 2005-007 via the Software Update pane and installed it on several PowerBooks, Power Mac G5s, G4 Cubes and iMac G5s without incident. Brief use turned up no apparent difficulties. [Bill Fox, Dana Baggett and Bob Manka]
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?