Brief Hands-On Report--Apple Security Update 2006-002

Apple just released Security Update 2006-002 for MacIntels, PPC Macs and PPC Mac Servers running Mac OS X 10.4.5 or 10.3.9.They are available via the automatic Software Update application and as stand-alone updaters (10.4.5 (Intel), 10.4.5 (PPC Client & Server), 10.3.9 Client and 10.3.9 Server). This update adds security and fixes issues introduced by Security Update 2006-001. According to a CNet quote of Bud Tribble, Apple's vice president of software technology,

"This Security Update includes some upgrades to our download validation mechanism and strengthens it. We reduced the number of false positives it gives."

The Read Me file which reads in part,

Security Update 2006-002 is recommended for all users and improves the reliability and security of the following components:

apache_mod_php
CoreTypes
LaunchServices
Mail
Safari
rsync

Additionally, this update incorporates Security Update 2006-001....

Here are further details,

Security Update 2006-002 [...] addresses the following issues:

CoreTypes-- Remote web sites can cause JavaScript to bypass the
same-origin policy
Description: When documents containing Javascript are loaded
from a remote site, data access is restricted by the same-origin
policy. However, under certain situations, maliciously-crafted
archives can cause these restrictions to be bypassed. This
update addresses the issue by flagging these documents as
unsafe.

Mail--Double-clicking an attachment in Mail may result in
arbitrary code execution
Description: By preparing a specially-crafted email message with
attachments, and enticing a user to double-click on that
attachment within Mail, an attacker may trigger a buffer
overflow. This could result in the execution of arbitrary code
with the privileges of the user running Mail. This issue
addresses the issue by performing additional bounds checking.
This issue does not affect systems prior to Mac OS X v10.4.
Credit to Kevin Finisterre of DigitalMunition for reporting this
issue.

Safari, LaunchServices, CoreTypes--Viewing a malicious web site may result in arbitrary
code execution
Description: Security Update 2006-001 addressed an issue where
Safari could automatically open a file which appears to be a
safe file type, such as an image or movie, but is actually an
application. This update provides additional checks to identify
variations of the malicious file types addressed in Security
Update 2006-001 so that they are not automatically opened. This
issue does not affect systems prior to Mac OS X v10.4. Credit to
Will Dormann of CERT/CC and Andris Baumberger for reporting
several of these issues.

The following non-security issues introduced by Security Update
2006-001 are also addressed by this update:

  • Download Validation: Security Update 2006-001 could cause the
    user to be warned when provided with certain safe file types,
    such as Word documents, or folders containing custom icons.
    These unneeded warnings are removed with this update.
  • apache_mod_php: A regression in PHP 4.4.1 that could prevent
    SquirrelMail from functioning is corrected with this update.
  • rsync: A regression in rsync that prevented the "--delete"
    command line option from functioning is corrected with this
    update.

We downloaded Security Update 2006-002 via Software Update and installed it on MacIntels (iMac and Mac mini) plus a Power Mac G5, Power Mac G4, iMac G5, Mac mini G4 and PowerBook G4. No problems were encountered while updating nor during hours of use since applying the update.

For some reason, installation of Security Update 2006-002 also appears to have fixed an AirPort Express connection problem that appeared after installing Security Update 2006-001. We have had a persistant failure of our 2GHz 20" iMac Core Duo to automatically connect with our AirPort Express network on startup. Many startups later we are still automatically connecting but are not sure why this update appears so far to have fixed the problem. [Bill Fox & Dana Baggett]



Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Security · This month in the archive