Brief Hands-On Report--Apple Released Mac OS X 10.4.7 Update
Here is a summary of the fixes in the 10.4.7 update:
The 10.4.7 Update is recommended for all users and includes general operating system fixes, as well as specific fixes for the following applications and technologies. It includes fixes for:
- preventing AFP deadlocks and dropped connections
- saving Adobe and Quark documents to AFP mounted volumes
- Bluetooth file transfers, pairing and connecting to a Bluetooth mouse, and syncing to mobile phones
- audio playback in QuickTime, iTunes, Final Cut Pro, and Soundtrack applications
- ensuring icons are spaced correctly when viewed on desktop
- determining the space required to burn folders
- iChat audio and video connectivity, creating chat rooms when using AIM
- importing files into Keynote 3
- PDF workflows when using iCal and iPhoto
- reliable use of Automator actions within workflows
- importing and removing fonts in Font Book
- syncing addresses, bookmarks, calendar events and files to .Mac
- compatibility with third party applications and devices
- previous standalone security updates
This Apple Web page provides further details on the fixes for Mail, iChat, Syncing, Finder, Apple applications, third-party applications, networking, Xsan and others.
Here are the specific details of the security fixes:
AFP (CVE-ID: CVE-2006-1468)--File and folder names may be disclosed to unauthorized users
Description: An issue in AFP server allows search results to include the names of files and folders for which the user performing the search has no access. This could result in information disclosure if the names themselves are sensitive information. This update addresses the issue by ensuring that
search results only include items for which the user is authorized. This issue does not affect systems prior to Mac OS X v10.4.ClamAV (CVE-ID: CVE-2006-1989)--When virus scanning is configured to update automatically, a malicious database mirror may cause arbitrary code execution
Description: An issue in ClamAV's automatic virus database updating may result in a stack-based buffer overflow. A malicious or spoofed ClamAV database mirror may be able to cause arbitrary code execution with the privileges of ClamAV. The Mail service, virus scanning, and automatic virus database updates are off by default. This update addresses the issue by incorporating ClamAV 0.88.2. This issue does not affect systems prior to Mac OS X v10.4.ImageIO (CVE-ID: CVE-2006-1469)--Viewing a maliciously-crafted TIFF image may result in an application crash or arbitrary code execution
Description: By carefully crafting a corrupt TIFF image, an attacker can trigger a stack-based buffer overflow which may result in an application crash or arbitrary code execution. This update addresses the issue by performing additional validation of TIFF images. This issue does not affect systems prior to Mac OS X v10.4.launchd (CVE-ID: CVE-2006-1471)--Local users may gain elevated privileges
Description: A format string vulnerability in the setuid program launchd may allow an authenticated local user to execute arbitrary code with system privileges. The issue is present in launchd's logging facility. This update addresses the issue by performing additional validation when logging messages. This issue does not affect systems prior to Mac OS X v10.4. Credit to Kevin Finisterre of DigitalMunition for reporting this issue.OpenLDAP (CVE-ID: CVE-2006-1470)--Remote attackers may cause Open Directory server to crash
Description: By carefully crafting an invalid LDAP request, a remote attacker may be able to trigger an assertion in the OpenLDAP server, resulting in a denial-of-service. This update addresses the issue by discarding the invalid request. This issue does not affect systems prior to Mac OS X v10.4. Credit to the Mu Security research team for reporting this issue.
We downloaded and installed Mac OS X 10.4.7 Update using the Software Update application on a number of Macs: an Intel-based 15" MacBook Pro and a 20" iMac Core Duo and a PowerPC-based 17" Power Book G4 and Power Mac G5. No difficulties were encountered with installation and our PowerPC-based Macs did NOT double restart after installation as we have seen others claim. After many hours use since installing Mac OS X 10.4.7, we have encountered no difficulties with any of our applications on any of our Macs.
We have noticed at least one obvious performance improvement in this update. Apple Mail on our Intel-based Macs is now much faster at checking mail boxes, especially IMAP accounts. We do not know if this performance improvement is due to a networking fix or a Mail fix or both since both components have been updated but it is very welcome. [Bill Fox & Dana Baggett]
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?