Hands-On Report--Apple Security Update 2005-007 for Mac OS X 10.4.2 and 10.3.9

This extensive security update is available for Mac OS X 10.4.2 and 10.3.9 Client and Server editions via the System Preferences Software Update pane. They are also available as standalone updaters from this Apple Web page.

From the 10.4.2 Client Read Me file,

Security Update 2005-007 delivers a number of security enhancements and is recommended for all Macintosh users. This update includes the following components:

AppKit
BlueTooth
CoreFoundation
cups
Directory Services
HIToolBox
Kerberos
loginwindow
Mail
OpenSSL
QuartzComposerScreenSaver
Security Interface
Safari
X11
zlib

From the 10.4.2 Server Read Me file,

Security Update 2005-007 delivers a number of security enhancements and is recommended for all Macintosh users.

This update includes the following components:

apache2
AppKit
blojsom
BlueTooth
CoreFoundation
cups
Directory Services
HIToolBox
Kerberos
loginwindow
Mail
OpenSSL
QuartzComposerScreenSaver
Security Interface
servermgrd
servermgr_ipfilter
SquirrelMail
Safari
X11
zlib

Here is a selected listing of the details:

AppKit
CVE-ID: CAN-2005-2501

Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.2, Mac OS X Server v10.4.2

Impact: Opening a malicious, rich text file could lead to arbitrary code execution.

Description: A buffer overflow in the handling of maliciously crafted rich text files could lead to arbitrary code execution. This update prevents the buffer overflow from occuring.

AppKit
CVE-ID: CAN-2005-2502

Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.2, Mac OS X Server v10.4.2

Impact: Opening a maliciously crafted Microsoft Word .doc file could result in arbitrary code execution.

Description: A buffer overflow in AppKit that is responsible for reading Word documents could allow arbitrary code execution. Only applications such as TextEdit that use AppKit to open Word documents are vulnerable. Microsoft Word for Mac OS X is not vulnerable. This update prevents the buffer overflow.

Bluetooth
CVE-ID: CAN-2005-2504

Available for: Mac OS X v10.4.2, Mac OS X Server v10.4.2

Impact: The System Profiler information about whether or not a Bluetooth device requires authentication is misleading.

Description: Selecting "Require pairing for security" in Bluetooth preferences correctly sets the device to require authentication, but in System Profiler the device is labeled with "Requires Authentication: No." This update changes System Profiler to accurately reflect the Bluetooth security settings. This issue does not affect systems prior to Mac OS X 10.4. Credit to John M. Glenn of San Francisco for reporting this issue.

CUPS
CVE-ID: CAN-2005-2525, CAN-2005-2526

Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.2, Mac OS X Server v10.4.2

Impact: The CUPS printing service will not print unless it is restarted.

Description: When handling multiple, simultaneous, print jobs, the CUPS printing service can stop printing because it incorrectly tracks open file descriptors. In addition, if CUPS receives a partial IPP request and a client terminates the connection, the printing service will then consume all available CPUs. If the service is restarted, then printing will resume. This update corrects the handling of multiple, simultaneous print jobs and partial requests.

HItoolbox
CVE-ID: CAN-2005-2513

Available for: Mac OS X v10.4.2, Mac OS X Server v10.4.2

Impact: VoiceOver may read content from secure input fields.

Description: Under certain circumstances, secure input fields may be read by VoiceOver services. This update stops VoiceOver from exposing the content of these fields. This issue does not affect systems prior to Mac OS X v10.4.

loginwindow
CVE-ID: CAN-2005-2509

Available for: Mac OS X v10.4.2, Mac OS X Server v10.4.2

Impact: A user can gain access to other logged-in accounts if Fast User Switching is enabled.

Description: An error in the handling of Fast User Switching can allow a local user who knows the password for two accounts to log into a third account without knowing the password. This update corrects the authentication error. This issue does not affect systems prior to Mac OS X 10.4. Credit to Sam McCandlish for reporting this issue.

Mail
CVE-ID: CAN-2005-2512

Available for: Mac OS X v10.4.2, Mac OS X Server v10.4.2

Impact: Loss of privacy due to Mail loading remote images in HTML emails.

Description: When Mail.app is used to print or forward an HTML message, it will attempt to load remote images even if a user's preferences disallow it. As this network traffic is not expected, it may be considered a privacy leak. This update addresses the issue by having Mail.app only load remote images in HTML messages when the preferences allow it. This issue does not affect systems prior to Mac OS X v10.4. Credit to Brad Miller of CynicalPeak and John Pell of Foreseeable Solutions for reporting this issue.

For the full detailed information on this update, see this Apple Web page.

We downloaded Security Update 2005-007 via the Software Update pane and installed it on several PowerBooks, Power Mac G5s, G4 Cubes and iMac G5s without incident. Brief use turned up no apparent difficulties. [Bill Fox, Dana Baggett and Bob Manka]



Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Security · This month in the archive