Apple Posted Security Update 2006-004 for Mac Pro and Mac OS X Server 10.4.7 (Universal)

The Mac Pro was just announced on Monday and there is already a security update for it to bring it into line with others running Mac OS X 10.4.7 with Security Update 2006-004 released August 1st. It has all of the security features released in Security Update 2006-004 except two. They are:

ImageIO
CVE-ID: CVE-2006-3459, CVE-2006-3461, CVE-2006-3462, CVE-2006-3465
Available for: Mac OS X v10.4.7 Build 8K1079, Mac OS X Server
v10.4.7 Build 8K1079
Impact: Viewing a maliciously-crafted TIFF image may lead to an
application crash or arbitrary code execution
Description: Buffer overflows were discovered in TIFF tag handling
(CVE-2006-3459, CVE-2006-3465), the TIFF PixarLog decoder
(CVE-2006-3461), and the TIFF NeXT RLE decoder (CVE-2006-3462). By
carefully crafting a corrupt TIFF image, an attacker can trigger a
buffer overflow which may lead to an application crash or arbitrary
code execution. This update addresses the issue by performing
additional validation of TIFF images. Systems prior to Mac OS X v10.4
are affected only by the TIFF NeXT RLE decoder issue (CVE-2006-3462).
Credit to Tavis Ormandy, Google Security Team for reporting this
issue. Note: A fifth issue discovered by Tavis Ormandy,
CVE-2006-3460, does not affect Mac OS X.

OpenSSH
CVE-ID: CVE-2006-0393
Available for: Mac OS X v10.4.7 Build 8K1079, Mac OS X Server
v10.4.7 Build 8K1079
Impact: When remote login is enabled, remote attackers may cause a
denial of service or determine whether an account exists
Description: Attempting to log in to an OpenSSH server ("Remote
Login") using a nonexistent account causes the authentication process
to hang. An attacker can exploit this behavior to detect the
existence of a particular account. A large number of such attempts
may lead to a denial of service. This update addresses the issue by
properly handling attempted logins by nonexistent users. This issue
does not affect systems prior to Mac OS X v10.4. Credit to Rob
Middleton of the Centenary Institute (Sydney, Australia) for
reporting this issue.

Security Update 2006-004 for Mac Pro is provided only for systems running Mac OS X v10.4.7 Build 8K1079 or Mac OS X Server v10.4.7 Build 8K1079 to reach the full security level provided with Security Update 2006-004 (August 1 release).

Security Update 2006-004 for Mac Pro is available via the Software Update application or from this Apple Web page. [Bill Fox]

Saw something? Send a tip or a correction

The archive ran on reader tips. What did you see, where, and do you want the credit? Something wrong on this page? Say so and it gets fixed.

Read by the editor. You get a copy by email. Never published without your say.

More in Security · This month in the archive