Apple fixes a dozen vulnerabilities affecting Mac OS X 10.5 and 10.6 in its first security update for the year released on Wednesday.
The security update addresses several issues with the Flash Player plug-in, including one that could allow an attacker to take control of the computer if the user visits a malicious Web site.
Also patched were holes in CoreAudio, ImageIO, and Image RAW that could lead to arbitrary code execution and allow an attacker to take control of the computer if a malicious MP4 audio file were played, or malicious TIFF (Tagged Image File Format) or DNG (Digital Negative) images were viewed.
The release also affects OpenSSL, fixing a man-in-the-middle vulnerability that exists in the SSL (Secure Sockets Layer) and TLS (Transport Layer Security) protocols used to secure communications over the Internet. The vulnerability, discovered by researchers at PhoneFactor in August 2009, could allow someone to capture data or modify operations performed in protected sessions.
In addition, a hole in the CUPS printing service was plugged that could allow an attacker to cause a remote denial-of-service by issuing a malicious get-printer-jobs request.
Apple - USE TAG
reading•Apple fixes a dozen holes in Mac OS X
Oct 17•Samsung carves faster processors with new, sharper light scalpel
Oct 17•The Red Hydrogen One is out this week: Here's everything you need to know
Oct 17•iPhone XR: Why the cheapest 2018 iPhone might be the one you want
Oct 17•Apple's privacy portal now lets US customers download their data