Hands-On Report--Security Update 2007-005--We had some troubles
Security Update 2007-005 is recommended for all users and improves the security of the following components:
bind
CarbonCore
CoreGraphics
crontabs
fetchmail
file
iChat
mDNSResponder
PPP
ruby
screen
texinfo
VPNSecurity Update 2007-004 has been incorporated into this security update.
Here are the security details:
Alias Manager--CVE-2007-0740--In certain circumstances, an implementation issue in Alias Manager will not show identically-named files contained in identically-named mounted disk images. By enticing a user to mount two identically-named disk images, an attacker could mislead the user into opening a malicious program. This update addresses the issue by performing additional validation of mountpaths. Credit to Greg Bolsinga of Blurb, Inc. for reporting
this issue.BIND--CVE-2007-0493, CVE-2007-0494, CVE-2006-4095,CVE-2006-4096--BIND is updated to version 9.3.4. Further information is available via the ISC web site at http://www.isc.org/index.pl?/sw/bind/
CoreGraphics--CVE-2007-0750--An integer overflow vulnerability exists in the handling of PDF files. By enticing a user to open a maliciously crafted PDF file, an attacker could trigger the overflow which may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation of PDF files. This issue does not affect systems prior to Mac OS X v10.4.
crontabs--CVE-2007-0751--Filesystems mounted in the /tmp directory may be deleted when the daily cleanup script is executed, which may lead to a denial of service. This update addresses the issues by updating the daily cleanup script to prevent find commands from descending into mounted filesystems.
fetchmail--CVE-2007-1558--fetchmail is updated to version 6.3.8 to address a cryptographic weakness that could lead to the disclosure of fetchmail passwords. Further information is available via the fetchmail web site at http://fetchmail.berlios.de/fetchmail-SA-2007-01.txt
file--CVE-2007-1536--A heap buffer overflow vulnerability exists in the
file command line tool, which may lead to an unexpected application termination or arbitrary code execution. This update addresses by performing additional validation of files that are passed to the file command.iChat--CVE-2007-2390--A buffer overflow vulnerability exists in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) code used to create Port Mappings on home NAT gateways in iChat. By sending a maliciously crafted packet, an attacker on the local network can trigger the overflow which may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation when processing UPnP protocol packets in iChat.
mDNSResponder--CVE-2007-2386--A buffer overflow vulnerability exists in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) code used to create Port Mappings on home NAT gateways in the OS X mDNSResponder implementation. By sending a maliciously crafted packet, an attacker on the local network can trigger the overflow which may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation when processing UPnP protocol packets. This issue does not affect systems prior to Mac OS X v10.4. Credit to Michael Lynn of Juniper Networks for reporting this issue.
PPP--CVE-2007-0752--An implementation issue exists in the PPP daemon when loading plugins via the command line, which allows a local user to obtain system privileges. This update addresses the issue by allowing only the superuser to load plugins. This issue does not affect systems prior to Mac OS X v10.4. Credit to an anonymous researcher working with the iDefense VCP for reporting this issue.
ruby--CVE-2006-5467, CVE-2006-6303--Multiple denial of service issues exist in the Ruby CGI library. By sending maliciously crafted HTTP requests to a web application using cgi.rb, an attacker could trigger an issue which may lead to a denial of service. This update addresses the issues by applying the Ruby patches.
screen--CVE-2006-4573--The screen command line tool is updated to address multiple denial of service vulnerabilities. Further information
is available via the GNU web site at http://lists.gnu.org/archive/html/screen-users/2006-10/msg00028.htmltexinfo--CVE-2005-3011--A file handling issue exists in texinfo, which may allow a local user to create or overwrite files with the privileges of the user running texinfo. This update addresses the issue through improved handling of temporary files.
VPN--CVE-2007-0753--A format string vulnerability exists in vpnd. By running the vpnd command with maliciously crafted arguments, a local user can trigger the vulnerability which may lead to arbitrary code execution with system privileges. This update addresses the issue by performing additional validation of the arguments passed to vpnd. Credit to Chris Anley of NGSSoftware for reporting this issue.
We downloaded and installed Security Update 2007-005 on a number of Intel-based and PowerPC-based Macs: Mac mini Core Duo, iMac Core Duo, iMac Core 2 Duo, MacBook Pro Core 2 Duo, PowerMac G4 Cube and PowerBook G4. With one exception, all went well. For those that went well, each Mac double restarted and took longer than normal at the gray Apple gear turning screen and the blue screen before the login window appears. Subsequent reboots were normal.
Our lone problem was with a 15" 2.33GHz MacBook Pro Core 2 Duo. When we rebooted after the installation finished, we were met with a solid light gray screen and ultimately the fans running full blast. We forced a shutdown and booted again only to be met with no video. We rebooted twice more but got a light gray screen with dark gray Apple logo but no spinning gear both times. Then we disconnected everything that was attached: external monitor, iPod, USB mouse and a SATA ExpressCard 34 connected to two external hard disk drives and booted again. This time the MacBook Pro behaved as the other Macs had, double reboot and all. A check with Disk Utility showed a minor problem that it fixed when we booted off an external drive.
Other Macs had peripherals attached but encountered no problems. Still, it seems a good idea to remove all external devices when updating Mac OS X. [Bill Fox]
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?