Apple fixes a dozen vulnerabilities affecting Mac OS X 10.5 and 10.6 in its first security update for the year released on Wednesday.
The security update addresses several issues with the Flash Player plug-in, including one that could allow an attacker to take control of the computer if the user visits a malicious Web site.
Also patched were holes in CoreAudio, ImageIO, and Image RAW that could lead to arbitrary code execution and allow an attacker to take control of the computer if a malicious MP4 audio file were played, or malicious TIFF (Tagged Image File Format) or DNG (Digital Negative) images were viewed.
The release also affects OpenSSL, fixing a man-in-the-middle vulnerability that exists in the SSL (Secure Sockets Layer) and TLS (Transport Layer Security) protocols used to secure communications over the Internet. The vulnerability, discovered by researchers at PhoneFactor in August 2009, could allow someone to capture data or modify operations performed in protected sessions.
In addition, a hole in the CUPS printing service was plugged that could allow an attacker to cause a remote denial-of-service by issuing a malicious get-printer-jobs request.
reading•Apple fixes a dozen holes in Mac OS X
Apr 24•Apple hires former Samsung vice president to tackle Korea: report
Apr 23•Apple v. Samsung retrial won't see Cook, Ive take the stand
Apr 23•iPhone SE 2 could get wireless charging, like iPhone X
Apr 23•J. Cole's KOD snags title from Drake for most-streamed album