Apple patches 13 Mac OS X vulnerabilities
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhy7nNSVj-nVickkFnBZcHefl9Bi4cVRPnbaFvuhggexNNjGO-HU0yRCDUSac-2UhxVbh1XUic9COsBA8xCCAcA_5cT_h6rYuds0Ry5tVE6Ehntl72AKjK1yOCOSqC7hYPAwndG9sEuMvc/s320/appl_logo.jpg)
The patch includes fixes for security holes in several open-source components, including ClamAV and PHP.
Here’s a quick look at the vulnerabilities and affected components.
* CVE-2010-1808: A stack buffer overlow exists in Apple Type Services’ handling of embedded fonts. Viewing or downloading a document containing a maliciously crafted embedded font may lead to arbitrary code execution.
* CVE-2010-1800: CFNetwork permits anonymous TLS/SSL connections. This may allow a man-in-the-middle attacker to redirect connections and intercept user credentials or other sensitive information. This issue does not affect the Mail application. This issue is addressed by disabling anonymous TLS/SSL connections. This issue does not affect systems prior to Mac OS X v10.6.3.
Continue reading
Comments
Post a Comment