Brief Hands-On Report--Apple Security Update 2006-002
"This Security Update includes some upgrades to our download validation mechanism and strengthens it. We reduced the number of false positives it gives."
The Read Me file which reads in part,
Security Update 2006-002 is recommended for all users and improves the reliability and security of the following components:
apache_mod_php
CoreTypes
LaunchServices
Safari
rsyncAdditionally, this update incorporates Security Update 2006-001....
Here are further details,
Security Update 2006-002 [...] addresses the following issues:
CoreTypes-- Remote web sites can cause JavaScript to bypass the
same-origin policy
Description: When documents containing Javascript are loaded
from a remote site, data access is restricted by the same-origin
policy. However, under certain situations, maliciously-crafted
archives can cause these restrictions to be bypassed. This
update addresses the issue by flagging these documents as
unsafe.Mail--Double-clicking an attachment in Mail may result in
arbitrary code execution
Description: By preparing a specially-crafted email message with
attachments, and enticing a user to double-click on that
attachment within Mail, an attacker may trigger a buffer
overflow. This could result in the execution of arbitrary code
with the privileges of the user running Mail. This issue
addresses the issue by performing additional bounds checking.
This issue does not affect systems prior to Mac OS X v10.4.
Credit to Kevin Finisterre of DigitalMunition for reporting this
issue.Safari, LaunchServices, CoreTypes--Viewing a malicious web site may result in arbitrary
code execution
Description: Security Update 2006-001 addressed an issue where
Safari could automatically open a file which appears to be a
safe file type, such as an image or movie, but is actually an
application. This update provides additional checks to identify
variations of the malicious file types addressed in Security
Update 2006-001 so that they are not automatically opened. This
issue does not affect systems prior to Mac OS X v10.4. Credit to
Will Dormann of CERT/CC and Andris Baumberger for reporting
several of these issues.The following non-security issues introduced by Security Update
2006-001 are also addressed by this update:
- Download Validation: Security Update 2006-001 could cause the
user to be warned when provided with certain safe file types,
such as Word documents, or folders containing custom icons.
These unneeded warnings are removed with this update.- apache_mod_php: A regression in PHP 4.4.1 that could prevent
SquirrelMail from functioning is corrected with this update.- rsync: A regression in rsync that prevented the "--delete"
command line option from functioning is corrected with this
update.
We downloaded Security Update 2006-002 via Software Update and installed it on MacIntels (iMac and Mac mini) plus a Power Mac G5, Power Mac G4, iMac G5, Mac mini G4 and PowerBook G4. No problems were encountered while updating nor during hours of use since applying the update.
For some reason, installation of Security Update 2006-002 also appears to have fixed an AirPort Express connection problem that appeared after installing Security Update 2006-001. We have had a persistant failure of our 2GHz 20" iMac Core Duo to automatically connect with our AirPort Express network on startup. Many startups later we are still automatically connecting but are not sure why this update appears so far to have fixed the problem. [Bill Fox & Dana Baggett]
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?