Apple releases wide-ranging OS X security update

Opinion
Nov 30, 20061 min

* Patches from Apple, Debian, Gentoo, others * Patient data exposed in two separate security breaches, and other interesting reading

Today’s bug patches and security alerts:

Apple releases wide-ranging OS X security update

A new update from Apple fixes multiple flaws in its OS X operating system. Application affected include: AirPort, ATS, CFNetwork, ClamAV, Finder, ftpd, GnuZip, Installer, OpenSSL, perl, php, PPP, Samba, Security Framework, VPN and WebKit.

Related US-CERT advisory

**********

Five new patches from Gentoo:

Kile (file permissions, data leak)

Ingo H3 (Shell command injection)

Mono (file overwrite)

LHa (multiple flaws)

OpenLDAP (denial of service)

**********

Two new updates from Debian:

Texinfo (multiple flaws)

pstotext (Shell command injection)

**********

Five new fixes from Ubuntu:

GnuPG (buffer overflow, code execution)

KOffice (integer overflow, code execution)

Dovecot (denial of service, code execution)

ImageMagick (multiple flaws)

tar (file overwrite)

**********

Three new patches from rPath:

libpng (denial of service)

ImageMagick (multiple flaws)

Texinfo (multiple flaws)

**********

From the interesting reading department:

Patient data exposed in two separate security breaches

Protected health information belonging to more than 45,000 people has been compromised in two separate incidents disclosed this week. Computerworld, 11/29/06.

PKI will grow, but policy problems remain

Public key infrastructure is poised for a resurgence, with associated identity technologies increasingly underpinning applications as organizations look to securely share information, vendors said Tuesday at a standards conference in London. IDG News Service, 11/28/06.