Apple Posted Security Update 2006-004 for Mac Pro and Mac OS X Server 10.4.7 (Universal)

The Mac Pro was just announced on Monday and there is already a security update for it to bring it into line with others running Mac OS X 10.4.7 with Security Update 2006-004 released August 1st. It has all of the security features released in Security Update 2006-004 except two. They are:

ImageIO
CVE-ID: CVE-2006-3459, CVE-2006-3461, CVE-2006-3462, CVE-2006-3465
Available for: Mac OS X v10.4.7 Build 8K1079, Mac OS X Server
v10.4.7 Build 8K1079
Impact: Viewing a maliciously-crafted TIFF image may lead to an
application crash or arbitrary code execution
Description: Buffer overflows were discovered in TIFF tag handling
(CVE-2006-3459, CVE-2006-3465), the TIFF PixarLog decoder
(CVE-2006-3461), and the TIFF NeXT RLE decoder (CVE-2006-3462). By
carefully crafting a corrupt TIFF image, an attacker can trigger a
buffer overflow which may lead to an application crash or arbitrary
code execution. This update addresses the issue by performing
additional validation of TIFF images. Systems prior to Mac OS X v10.4
are affected only by the TIFF NeXT RLE decoder issue (CVE-2006-3462).
Credit to Tavis Ormandy, Google Security Team for reporting this
issue. Note: A fifth issue discovered by Tavis Ormandy,
CVE-2006-3460, does not affect Mac OS X.

OpenSSH
CVE-ID: CVE-2006-0393
Available for: Mac OS X v10.4.7 Build 8K1079, Mac OS X Server
v10.4.7 Build 8K1079
Impact: When remote login is enabled, remote attackers may cause a
denial of service or determine whether an account exists
Description: Attempting to log in to an OpenSSH server ("Remote
Login") using a nonexistent account causes the authentication process
to hang. An attacker can exploit this behavior to detect the
existence of a particular account. A large number of such attempts
may lead to a denial of service. This update addresses the issue by
properly handling attempted logins by nonexistent users. This issue
does not affect systems prior to Mac OS X v10.4. Credit to Rob
Middleton of the Centenary Institute (Sydney, Australia) for
reporting this issue.

Security Update 2006-004 for Mac Pro is provided only for systems running Mac OS X v10.4.7 Build 8K1079 or Mac OS X Server v10.4.7 Build 8K1079 to reach the full security level provided with Security Update 2006-004 (August 1 release).

Security Update 2006-004 for Mac Pro is available via the Software Update application or from this Apple Web page. [Bill Fox]

Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Security · This month in the archive