Brief Hands-On Report--Mac OS X Security Update 2006-003 (Intel and PowerPC versions)

Apple released Security Update 2006-003 for Intel- and PowerPC-based Macs and for Mac OS X 10.3.9 and 10.4.6, client and server editions. It is available for download via the Software Update application or from this Apple Web page. According to the ReadMe file,

Security Update 2006-003 is recommended for all users and improves the security of the following components.

AppKit
Bom
CFNetwork
CoreFoundation
CoreGraphics
curl
Finder
ImageIO
LaunchServices
Mail
Preview
QuickDraw
Ruby
Safari
securityd

Here are the details on this security update,

AppKit CVE-2006-1439 Characters entered into a secure text field can be read by other applications in the same window session
Description: Under certain circumstances when switching between
text input fields, NSSecureTextField may fail to re-enable
secure event input. This may allow other applications in the
same window session to see some input characters and keyboard
events. This update addresses the issue by ensuring secure event
input is properly enabled. This issue does not affect systems
prior to Mac OS X v10.4.

AppKit, ImageIO CVE-2006-1982, CVE-2006-1983, CVE-2006-1984 Viewing a maliciously-crafted GIF or TIFF image may lead
to arbitrary code execution
Description: The handling of malformed GIF or TIFF image may
lead to arbitrary code execution when parsing a
maliciously-crafted image. This affects applications that use
the ImageIO (Mac OS X v10.4 Tiger) or AppKit (Mac OS X v10.3
Panther) framework to read images. This update addresses the
issue by performing additional validation of GIF and TIFF
images.

BOM CVE-2006-1985 Expanding an archive may lead to arbitrary code
execution
Description: By carefully crafting an archive (such as a Zip
archive) containing long path names, an attacker may be able to
trigger a heap buffer overflow in BOM. This may result in
arbitrary code execution. BOM is used to handle archives in
Finder and other applications. This update adresses the issue by
properly handling the boundary conditions.

BOM CVE-2006-1440 Expanding a malicious archive may cause arbitrary files
to be created or overwritten
Description: An issue in the handling of directory traversal
symbolic links encountered in archives may cause BOM to create
or overwrite files in arbitrary locations accessible to the user
expanding the archive. BOM handles archives on behalf of Finder
and other applications. This update addresses the issue by
ensuring that files expanded from an archive are not placed
outside the destination directory.

CFNetwork CVE-2006-144 Visiting malicious web sites may lead to arbitrary code execution
Description: An integer overflow in the handling of chunked
transfer encoding could lead to arbitrary code execution.
CFNetwork is used by Safari and other applications. This update
addresses the issue by performing additional validation. The
issue does not affect systems prior to Mac OS X v10.4.

ClamAV CVE-2006-1614, CVE-2006-1615, CVE-2006-1630 Processing maliciously-crafted email messages with ClamAV may lead to arbitrary code execution
Description: The ClamAV virus scanning software has been updated
to incorporate security fixes in the latest release. ClamAV was
introduced in Mac OS X Server v10.4 for email scanning. The most
severe of these issues could lead to arbitrary code execution
with the privileges of ClamAV. For more information, see the
project web site at http://www.clamav.net.

CoreFoundation CVE-2006-1442 Registration of an untrusted bundle may lead to arbitrary code execution
Description: Under certain circumstances, bundles are implicitly
registered by applications or the system. A feature of the
bundle API allows dynamic libraries to load and execute when a
bundle is registered, even if the client application does not
explicitly request it. As a result, arbitrary code may be
executed from an untrusted bundle without explicit user
interaction. This update addresses the issue by only loading and
executing libraries from the bundle at the appropriate time.

CoreFoundation CVE-2006-1443 String conversions to file system representation may lead to arbitrary code execution
Description: An integer underflow during the processing of a
boundary condition in CFStringGetFileSystemRepresentation may
lead to arbitrary code execution. Applications that use this API
or one of the related APIs such as NSFileManager's
getFileSystemRepresentation:maxLength:withPath: may trigger the
issue and lead to arbitrary code execution. This update adresses
the issue by properly handling the boundary conditions.

CoreGraphics CVE-2006-1444 Characters entered into a secure text field can be read by other applications in the same window session
Description: Quartz Event Services provides applications with
the ability to observe and alter low-level user input events.
Normally, applications cannot intercept events when secure event
input is enabled. However, if "Enable access for assistive
devices" is on, Quartz Event Services can be used to intercept
events even when secure event input is enabled. This update
addresses the issue by filtering events when secure event input
is enabled. This issue does not affect systems prior to Mac OS X
v10.4. Credit to Damien Bobillot for reporting this issue.

Finder CVE-2006-1448 Launching an Internet Location item may lead to
arbitrary code execution
Description: Internet Location items are simple URL containers
which may reference http://, ftp://, and file:// URLs, as well
as a few other URL schemes. These different types of Internet
Location items are visually distinct, and meant to be safe to
explicitly launch. However, the scheme of the URL may be
different than the Internet Location type. As a result, an
attacker may be able to convince a user to launch a supposedly
benign item (such as a Web Internet Location, http://), with the
result that some other URL scheme is actually used. In certain
circumstances, this may lead to arbitrary code execution. This
update addresses the issues by restricting the URL scheme based
on the Internet Location type.

FTPServer CVE-2006-1445 FTP operations by authenticated FTP users may lead to arbitrary code execution
Description: Multiple issues in FTP server path name handling
could result in a buffer overflow. A malicious authenticated
user may be able to trigger this overflow which may lead to
arbitrary code execution with the privileges of the FTP server.
This update adresses the issue by properly handling the boundary
conditions.

Flash Player CVE-2005-2628, CVE-2006-0024 Playing Flash content may lead to arbitrary code execution
Description: Flash Player contains critical vulnerabilities that
may lead to arbitrary code execution when specially-crafted
files are loaded. Further information is available via the
Macromedia web site at www.macromedia.com. This update addresses
the issue by incorporating Flash Player version 8.0.24.0.

ImageIO CVE-2006-1552 Viewing a maliciously-crafted JPEG image may lead to arbitrary code execution
Description: An integer overflow in the processing of JPEG
metadata may result in a heap buffer overflow. By carefully
crafting an image with malformed JPEG metadata, an attacker may
be able to cause arbitrary code execution when the image is
viewed. This update addresses the issue by performing additional
validation of images. This issue does not affect systems prior
to Mac OS X v10.4. Credit to Brent Simmons of NewsGator
Technologies, Inc. for reporting this issue.

Keychain CVE-2006-1446 An application may be able to use Keychain items when the Keychain is locked
Description: When a Keychain is locked, it is not possible for
applications to access the Keychain items it contains without
first requesting that the Keychain be unlocked. However, an
application that has obtained a reference to a Keychain item
prior to the Keychain being locked may, in certain
circumstances, be able to continue using that Keychain item
regardless of whether the Keychain is locked or unlocked. This
update addresses the issue by rejecting requests to use Keychain
items when the Keychain is locked. Credit to Tobias Hahn of HU
Berlin for reporting this issue.

LaunchServices CVE-2006-1447 Viewing a malicious web site may lead to arbitrary code execution
Description: Long file name extensions may prevent Download
Validation from correctly determining the application with which
an item may be opened. As a result, an attacker may be able to
bypass Download Validation and cause Safari to automatically
open unsafe content if the "Open `safe' files after downloading"
option is enabled and certain applications are not installed.
This update addresses the issue through improved checking of the
file name extension. This issue does not affect systems prior to
Mac OS X v10.4.

libcurl CVE-2005-4077 URL handling in libcurl may lead to arbitrary code execution
Description: The open source HTTP library libcurl contains
buffer overflows in URL handling. Applications using curl for
URL handling may trigger the issue and lead to arbitrary code
execution. This update addresses the issue by incorporating
libcurl version 7.15.1. This issue does not affect systems prior
to Mac OS X v10.4.

Mail CVE-2006-1449 Viewing a malicious mail message may lead to arbitrary code execution
Description: By preparing a specially-crafted email message with
MacMIME encapsulated attachments, an attacker may trigger an
integer overflow. This may lead to arbitrary code execution with
the privileges of the user running Mail. This issue corrects the
issue by performing additional validation of messages.

Mail CVE-2006-1450 Viewing a malicious mail message may lead to arbitrary code execution
Description: The handling of invalid color information in
enriched text email messages could cause the allocation and
initialization of arbitrary classes. This may lead to arbitrary
code execution with the privileges of the user running Mail.
This update addresses the issue by properly handling malformed
enriched text data.

MySQL Manager CVE-2006-1451 MySQL database may be accessed with an empty password
Description: During the initial setup of a MySQL database server
using MySQL Manager, the "New MySQL root password" may be
supplied. However, this password is not actually used. As a
result, the MySQL root password will remain empty. A local user
may then obtain access to the MySQL database with full
privileges. This update addresses the issue by ensuring that the
entered password is saved. This issue does not affect systems
prior to Mac OS X Server v10.4. Credit to Ben Low of the
University of New South Wales for reporting this issue.

Preview CVE-2006-1452 Navigating a maliciously-crafted directory hierarchy may lead to arbitrary code execution
Description: When navigating very deep directory hierarchies in
Preview, a stack buffer overflow may be trigger. By carefully
crafting such a directory hierarchy, it may be possible for an
attacker to cause arbitrary code execution if the directories
are opened in Preview. This issue does not affect systems prior
to Mac OS X v10.4.

QuickDraw CVE-2006-1453, CVE-2006-1454 Viewing a maliciously-crafted PICT image may lead to arbitrary code execution
Description: Two issues affect QuickDraw when processing PICT
images. Malformed font information may cause a stack buffer
overflow, and malformed image data may cause a heap buffer
overflow. By carefully crafting a malicious PICT image, an
attacker may be able to cause arbitrary code execution when the
image is viewed. This update addresses the issue by performing
additional validation of PICT images. Credit to Mike Price of
McAfee AVERT Labs for reporting this issue.

QuickTime Streaming Server CVE-2006-1455 A malformed QuickTime movie can cause QuickTime Streaming Server to crash
Description: A QuickTime movie that has a missing track may
cause a null pointer dereference, causing the server process to
crash. This causes active client connections to be interrupted.
However, the server is restarted automatically. This update
addresses the issue by producing an error when malformed movies
are encountered.

QuickTime Streaming Server CVE-2006-1456 Maliciously-crafted RTSP requests may lead to crashes or arbitrary code execution
Description: By carefully crafting an RTSP request, an attacker
may be able to trigger a buffer overflow during message logging.
This may lead to the arbitrary code execution with the
privileges of the QuickTime Streaming Server. This update
adresses the issue by properly handling the boundary conditions.
Credit to the Mu Security research team for reporting this
issue.

Ruby CVE-2005-2337 Ruby safe level restrictions may be bypassed
Description: The Ruby scripting language contains a mechanism
called "safe levels" that is used to restrict certain
operations. This mechanism is most commonly used when running
privileged Ruby applications or Ruby network applications. In
certain circumstances, an attacker may be able to bypass the
restrictions in such applications. Applications that do not rely
on safe levels are unaffected. This update addresses the issue
by ensuring that safe levels cannot be bypassed.

Safari CVE-2006-1457 Visiting malicious web sites may lead to file manipulation or arbitrary code execution
Description: When Safari's "Open `safe' files after downloading"
option is enabled, archives will be automatically expanded. If
the archive contains a symbolic link, the target symlink may be
moved to the user's desktop and launched. This update addresses
the issue by not resolving downloaded symbolic links. This issue
does not affect systems prior to Mac OS X v10.4.

Again to serve as your unofficial bleeding-edge tester, we downloaded Security Update 2006-003 via the Software Update application and installed it on an iMac Core Duo, MacBook Pro, Power Mac G4 Cube, iMac G5 and PowerBook G4. We ran into no problems doing so. After several hours use, we have not seen any issues. [Bill Fox]


Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Dark Side · This month in the archive