Categories: MacSecurityWorkspace

Apple Update Patches 13 Mac Vulnerabilities

Apple has released a security update that fixes a number of issues in several components, including CoreGraphics and Apple Type Services. Several of the vulnerabilities are buffer overflows, and can be exploited to execute arbitrary code.

According to the Apple advisory, the Apple Type Services (ATS) bug can be triggered by viewing or downloading a document containing a malicious embedded font. If exploited, hackers could use it to run code.

Apple said it fixed the issue through improved bounds checking.

A heap buffer overflow due to CoreGraphics’ handling of PDF files can also be exploited by attackers to run arbitrary code, and was likewise addressed with improved bounds checking.

Five of the vulnerabilities affect PHP, and were addressed by updating to PHP 5.3.1. A sixth PHP bug – a buffer overflow in PHP’s libpng library – was swatted by updating libpng within PHP to version 1.4.3. That last issue can be exploited via a malicious PNG image, and does not affect systems prior to Mac OS X v10, according to the advisory.

Other components affected by the update include: CFNetwork, libsecurity, Samba and ClamAV.

Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Share
Published by
Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Recent Posts

FTC Plans Investigation Into Microsoft Cloud Business – Report

Microsoft's cloud business practices are reportedly facing a potential anti-competitive investigation by the FTC

40 mins ago

Programmer Sentenced To Five Years In Prison For Bitcoin Laundering

Ilya Lichtenstein sentenced to five years in prison for hacking into a virtual currency exchange…

2 hours ago

Hate Speech Watchdog CCDH To Quit Musk’s X

Target for Elon Musk's lawsuit, hate speech watchdog CCDH, announces its decision to quit X…

19 hours ago

Meta Fined €798m Over Alleged Facebook Marketplace Violations

Antitrust penalty. European Commission fines Meta a hefty €798m ($843m) for tying Facebook Marketplace to…

21 hours ago

Elon Musk Rebuked By Italian President Over Migration Tweets

Elon Musk continues to provoke the ire of various leaders around the world with his…

22 hours ago

VW, Rivian Launch Joint Venture, As Investment Rises To $5.8 Billion

Volkswagen and Rivian officially launch their joint venture, as German car giant ups investment to…

23 hours ago