Brief Hands-On Report--Installing Mac OS X Security Update 2006-004
According to Apple,
Security Update 2006-004 is recommended for all users and improves the security of the following components.
AFP Server
Bluetooth
Bom
DHCP
dyld
fetchmail
gnuzip
ImageIO
LaunchServices
OpenSSH
telnet
WebKit
Here are the details:
AFP Server--CVE-ID: CVE-2006-1472--Impact: When file sharing is enabled, file and folder items may be disclosed to unauthorized users
AFP Server--CVE-ID: CVE-2006-1473--Impact: When file sharing is enabled, authenticated users may cause a crash or arbitrary code execution. Credit to Dino Dai Zovi of Matasano Security for reporting this issue.
AFP Server--CVE-ID: CVE-2006-3495--Impact: When file sharing is enabled, authenticated local users may be able to access files or folders of other users through AFP
AFP Server--CVE-ID: CVE-2006-3496--Impact: When file sharing is enabled, a maliciously-crafted AFP request may cause the AFP server to crash
AppKit, ImageIO--CVE-ID: CVE-2006-3459, CVE-2006-3461, CVE-2006-3462,CVE-2006-3465--Impact: Viewing a maliciously-crafted TIFF image may lead to an application crash or arbitrary code execution. Credit to Tavis Ormandy, Google Security Team for reporting this issue.
Bluetooth Setup Assistant--Impact: Passkey length increased for Bluetooth pairing
Bom--CVE-ID: CVE-2006-3497--Impact: Opening a maliciously-crafted archive may lead to an application crash or arbitrary code execution. Credit to Tom Ferris of Security-Protocols.com for reporting this issue.
DHCP--CVE-ID: CVE-2006-3498--Impact: When bootpd is enabled, a maliciously-crafted BOOTP request may cause arbitrary code execution
dyld--CVE-ID: CVE-2006-3499--Impact: Malicious local users may influence dynamic linker output with undesirable consequences. Credit to Neil Archibald of Suresec LTD for reporting this issue.
dyld--CVE-ID: CVE-2006-3500--Impact: Malicious local users may influence the loading of dynamic libraries in order to gain elevated privileges. Credit to Neil Archibald of Suresec LTD for reporting this issue.
fetchmail--CVE-ID: CVE-2005-2335, CVE-2005-3088, CVE-2005-4348, CVE-2006-0321--Impact: Multiple issues in the fetchmail utility may lead to denial of service or arbitrary code execution.
gunzip--CVE-ID: CVE-2005-0988--Impact: Malicious local users may be able to modify permissions of files owned by another user when the command line tool gunzip is run
gunzip--CVE-ID: CVE-2005-1228--Impact: Decompressing maliciously-crafted files with "gunzip -N" may lead to arbitrary file replacement or creation
Image RAW--CVE-ID: CVE-2006-0392--Impact: Viewing a maliciously-crafted Canon RAW image may lead to an application crash or arbitrary code execution
ImageIO--CVE-ID: CVE-2006-3501--Impact: Viewing a maliciously-crafted Radiance image may lead to an application crash or arbitrary code execution
ImageIO--CVE-ID: CVE-2006-3502--Impact: Viewing a maliciously-crafted GIF image may lead to an application crash or arbitrary code execution
ImageIO--CVE-ID: CVE-2006-3503--Impact: Viewing a maliciously-crafted GIF image may lead to an application crash or arbitrary code execution. Credit to Tom Ferris of Security-Protocols.com for reporting this issue.
LaunchServices--CVE-ID: CVE-2006-3504--Impact: Visiting a malicious web site could cause JavaScript to execute in the local domain
OpenSSH--CVE-ID: CVE-2006-0393--Impact: When remote login is enabled, remote attackers may cause a denial of service or determine whether an account exists. Credit to Rob Middleton of the Centenary Institute
(Sydney, Australia) for reporting this issue.telnet--CVE-ID: CVE-2005-0488--Impact: When the command line tool telnet is used to connect to a malicious TELNET server, environmental variables may be disclosed. Credit to Gael Delalleau and iDEFENSE for reporting this issue.
WebKit--CVE-ID: CVE-2006-3505--Impact: Visiting a malicious web site may lead to arbitrary code execution. Credit to Jesse Ruderman of Mozilla Corporation for reporting this issue.
We downloaded Security Update 2006-004 via Software Update and installed it on Intel- and PowerPC-based Macs: MacBook Pro, Mac mini, iMac Core Duo, PowerBook G4, Power Mac G4 Cube and iMac G5, all running 10.4.7 and one running 10.4.7 Server. We did not repair permissions in most cases and did not disconnect FireWire or USB devices. We encountered no problems in several hours of general use on any updated Mac. [Bill Fox & Dana Baggett]
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?