Brief Hands-On Report--Apple released Security Update 2006-008

Apple released Security Update 2006-008. It is available for download via Software Update or as stand-alone files from either of these Apple Web pages (Universal edition or PowerPC edition). According to the ReadMe file,

Security Update 2006-008 is recommended for all users and improves the security of the following components:

Quartz Composer
QuickTime for Java

The security details are as follows:

CVE-ID: CVE-2006-5681

Available for: Mac OS X v10.4.8, Mac OS X Server v10.4.8

Impact: Visiting a malicious web site may lead to information disclosure

Description: Java applets may use QuickTime for Java to obtain the images rendered on screen by embedded QuickTime objects and upload them to the originating web site. When this facility is used in conjunction with Quartz Composer, it becomes possible to capture images that may contain local information. This update addresses the issue by disallowing Quartz Composer compositions in unsigned Java applets. Quartz Composer compositions continue to function locally. Applications and signed Java applets that utilize QuickTime and QuickTime for Java are unaffected. This issue does not affect systems prior to Mac OS X v10.4. It also does not affect the Windows platform. Credit to Geoff Beier for reporting this issue.

We downloaded and installed the security patch on a number of Macs: PowerBook G4, Power Mac G4 Cube, 2GHz iMac Core Duo, 2.33GHz iMac Core 2 Duo and a 15" MacBook Pro Core 2 Duo. All went well with the installations and no issues were discovered while briefly using the updated computers running Mac OS X 10.4.8 client and server. [Bill Fox & Dana Baggett]

Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Security · This month in the archive