Brief Hands-On Report--Apple released Security Update 2007-002

Security Update 2007-002 is available via Software Update or as stand-alone updaters from these Apple Web pages:

According to Apple,

Security Update 2007-002 is recommended for all users and improves the security of the following components:

CoreServices
iChat
UserNotificationCenter

The details of Security Update 2007-002 are:

Finder
CVE-ID: CVE-2007-0197
Available for: Mac OS X v10.4.8, Mac OS X Server v10.4.8
Impact: Mounting a maliciously-crafted disk image may lead to an
application crash or arbitrary code execution
Description: A buffer overflow exists in Finder's handling of
volume names. By enticing a user to mount a malicious disk
image, an attacker could trigger this issue, which may lead to
an application crash or arbitrary code execution. A proof of
concept for this issue has been published on the Month of Apple
Bugs web site (MOAB-09-01-2007). This update addresses the issue
by performing additional validation of disk images. This issue
does not affect systems prior to Mac OS X v10.4. Credit to Kevin
Finisterre of DigitalMunition for reporting this issue.

iChat
CVE-ID: CVE-2007-0614, CVE-2007-0710
Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS
X v10.4.8, Mac OS X Server v10.4.8
Impact: Attackers on the local network may be able to cause
iChat to crash
Description: A null pointer dereference in iChat's Bonjour
message handling could allow a local network attacker to cause
an application crash. A proof of concept for this issue in Mac
OS X v10.4 has been published on the Month of Apple Bugs web
site (MOAB-29-01-2007). This update addresses the issues by
performing additional validation of Bonjour messages.

iChat
CVE-ID: CVE-2007-0021
Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS
X v10.4.8, Mac OS X Server v10.4.8
Impact: Visiting malicious websites may lead to an application
crash or arbitrary code execution
Description: A format string vulnerability exists in the iChat
AIM URL handler. By enticing a user to access a maliciously-crafted
AIM URL, an attacker can trigger the overflow, which may lead to an
application crash or arbitrary code execution. A proof of concept for
this issue has been published on the Month of Apple Bugs web site
(MOAB-20-01-2007). This update addresses the issue by performing
additional validation of AIM URLs.

UserNotification
CVE-ID: CVE-2007-0023
Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS
X v10.4.8, Mac OS X Server v10.4.8
Impact: Malicious local users may be able to obtain system
privileges
Description: The UserNotificationCenter process runs with
elevated privileges in the context of a local user. This may
allow a malicious local user to overwrite or modify system
files. A program that triggers this issue has been published on
the Month of Apple Bugs web site (MOAB-22-01-2007). This update
addresses the issue by having UserNotificationCenter drop its
group privileges immediately after launching.

We downloaded and installed this update with no problems on a MacBook Pro C2D and an iMac Core Duo running Mac OS X 10.4.8. In several hours subsequent use, we encountered no issues. [Bill Fox & Dana Baggett]

Saw something? Send a tip or a correction

The archive ran on reader tips. What did you see, where, and do you want the credit? Something wrong on this page? Say so and it gets fixed.

Read by the editor. You get a copy by email. Never published without your say.

More in Security · This month in the archive