Apple Patches 43 Flaws In OS, QuickTime

OS Mac

The Mac OS X upgrade, dubbed Security Update 2006-003, contains 31 fixes and ups the operating system to version 10.4.6. It was the third collective update of the OS since the first of the year.

According to information posted on the Apple support Web site, 2006-003 fixes one flaw in the Finder, two in both Flash Player and Mail, and one in Safari, along with 25 others. Although Apple doesn't rate the severity of the vulnerabilities it patches -- as does rival Microsoft -- 24 of the 31 could let a hacker execute his own code on a compromised Mac.

Several, in fact, read as particularly dangerous. The two affecting Mail, the operating system's e-mail client, could result in a Mac being hijacked if its user simply views a specially-crafted message, Apple said in its alert. The bug in Apple's Safari Web browser, meanwhile, can be exploited by drawing users to Web sites and duping them into downloading a malicious archive file.

In late April, researcher Tom Ferris disclosed 6 zero-day bugs in Mac OS X; the 2006-003 update fixed all of them, Ferris noted on his blog.

id
unit-1659132512259
type
Sponsored post

Also on Thursday, Apple rolled out a cumulative update for QuickTime, now tagged as version 7.1, that fixed a dozen flaws. All 12 affect both the Macintosh and Windows editions of the player.

While Mac users will automatically receive notification of both the Mac OS X and QuickTime updates via their machines' Software Update Feature, Windows users may need to download the update manually. When TechWeb queried for an update from within QuickTime for Windows v. 7.0.4, the player responded saying that no update was available.

The Mac OS X security update is available in versions specific to PowerPC- or Intel-based systems. Users who don't want to wait for Software Update to kick in can from the Apple site.