The Channel logo

News

By | John Leyden 29th May 2008 10:59

Apple mega update strikes out calendar bug

iPatch

Apple pushed out a bumper security and performance update on Wednesday that finally plugs a long-standing security hole.

Mac OS X version 10.5.3 updates open source components that Apple bundles with its software (such as Apache) as well as its own software and third party components. In total the software upgrade patches 22 modules, including a fix for a serious security bug in Apple's calendering application iCal.

Flaws in iCal that potentially created a means to inject hostile code onto vulnerable systems were discovered by Core Security back in January, and promptly notified to Apple. A protracted series of exchanges followed.

The dialogue revolved around whether the bugs were serious enough to patch and, if so, when Apple would issue patches. Eventually Core said it would publish an advisory on Wednesday (21 May) in the belief Apple was ready to release a fix on Monday (19 May). In the event, this update only came out on 28 May.

Apple now concedes that maliciously crafted iCalendar files might be used to smuggle malware onto unpatched systems. It credits Core Security with reporting the issue.

Other components of Mac OS X version 10.5.3 defend against other arbitrary code execution vulnerabilities, stomping on bugs in a Flash Player Plug-in for Mac OS X, Appkit and Mail. There's also fixes for a password disclosure vulnerability involving single sign-on and bugs in the kernel that might trigger unexpected system shutdown.

A full run-down of the security components of Apple's release can be found on its site here. ®

comment icon Read 42 comments on this article alert Send corrections

Opinion

Windows 10 on Surface 3

Tim Anderson

It's do-or-die for Microsoft's new operating system on 29 July
Wine Taps by N Wong, Flickr, CC 2.0 License

Simon Sharwood

Clouds sell compute by the glass. On-premises kitmakers want to sell wine-as-a-service

Greg Knieriemen

Privacy, security, information sovereignty, what we all want, right?
Microsoft's Joe Belfiore, speaking at Build 2015

Andrew Orlowski

Redmond devotees may as well have demanded manga desktop wallpaper

Features

Time to pull out the magnifying glass to swot up on those Ts&Cs
Android icon desktop toys
Nice devices, now speak 'enterprise' to me
Standard Form 86 reads like a biography of each intelligence worker
Protestor barricade image via Shutterstock
Breaking through the hardware barricades to a new network state