Aggiornamento Sicurezza

Notizie Apple, aggiornamenti, novità. Marketing e concorrenza. Eventi Speciali.
User avatar
Peterpan
Quintessenza di Mac Peer
Posts: 9823
Joined: Sat Jan 06, 2007 7:53 am
Aggiornamento Sicurezza

Post by Peterpan »

E' in arrivo un aggiornamento di sicurezza: cito da TUAW.

Apple has just posted its latest security update. This update addresses a boatload of possible vulnerabilities including a number of core unix utilities as well as iChat and VPN. Without further ado, here's a quick rundown of the fixes and the vulnerabilities:

Alias Manager. Impact: Users may be misled into opening a substituted file

BIND. Impact: Multiple vulnerabilities in BIND, the most serious of which is remote denial of service

CoreGraphics. Impact: Opening a maliciously crafted PDF file may lead to an unexpected application termination or arbitrary code execution

crontabs. Impact: The daily /tmp cleanup script may lead to a denial of service

fetchmail. Impact: fetchmail password disclosure may be possible

file. Impact: Running the file command on a maliciously crafted file may lead to an unexpected application termination or arbitrary code execution

iChat. Impact: An attacker on the local network may be able to cause a denial of service or arbitrary code execution

mDNSResponder. Impact: An attacker on the local network may be able to cause a denial of service or arbitrary code execution

PPP. Impact: A local user may obtain system privileges

ruby. Impact: Denial of service vulnerabilities in the Ruby CGI library

screen. Impact: Multiple denial of service vulnerabilities in GNU Screen

texinfo. Impact: A vulnerability in texinfo may allow arbitrary files to be overwritten

VPN. Impact: A local user may obtain system privileges
Chi non accetta critiche o discussioni e fa tutto per evitarle è un cialtrone, digli di smettere !!!
User avatar
avrobay
Posts: 28816
Joined: Sat Jan 22, 2005 2:15 pm

Post by avrobay »

Grazie :)

Scarichiamo!

Security Update 2007-005 è consigliato a tutti gli utenti e migliora la sicurezza dei seguenti componenti:

bind
CarbonCore
CoreGraphics
crontabs
fetchmail
file
iChat
mDNSResponder
PPP
ruby
screen
texinfo
VPN

A questo aggiornamento è stato incorporato l'aggiornamento Security Update 2007-004.

Per informazioni dettagliate su questo aggiornamento, consulta il sito web: http://docs.info.apple.com/article.html?artnum=61798-it.
Chi copia è un cialtrone. Digli di smettere! - Gianni Cresci
User avatar
meigel
Quintessenza di Mac Peer
Posts: 7917
Joined: Tue Oct 04, 2005 9:40 am
Re: Aggiornamento Sicurezza

Post by meigel »

Grazie della segnalazione... procedo! :)

Edit: il riavvio è stato "doppio" e piuttosto lungo (iMac G5 10.4.9) ;)
If your kids want to paint their bedrooms, as a favor to me, let ‘em do it.
Randy Pausch
Truzzo
Oracolo di Mac Peer
Posts: 3558
Joined: Thu Mar 08, 2007 9:55 pm

Post by Truzzo »

Riavvio mooooolto lento. Vi dirò di più, dopo cinque minuti di rotella che girava, ho dovuto effettuare uno shout down. (MBP 15" 10.4.9)
:?
Memento gAudere Semper
---------------------------------------
Ciò che nella vita reale mi ha sempre e ovunque ostacolato è stata la mia incapacità di farmi un'idea autentica della meschinità e della bassezza degli uomini. (A. Schopenhauer)
User avatar
avrobay
Posts: 28816
Joined: Sat Jan 22, 2005 2:15 pm

Post by avrobay »

Tutto ok (a parte il doppio riavvio-coccolone) sul G4 :)
Chi copia è un cialtrone. Digli di smettere! - Gianni Cresci
User avatar
Roxx
Amico di Mac Peer
Posts: 299
Joined: Sun Mar 11, 2007 9:44 pm

Post by Roxx »

anche io 2 riavvii , MacBook Pro 2,16 2 G ram, vecchio di un mese
User avatar
maverick
Eminenza Grigia di Mac Peer
Posts: 617
Joined: Wed May 31, 2006 1:20 am

Post by maverick »

anche io due riavvi,e anche un pò lenti,imac intel core duo 1,83ghz
imac intel 1.83 ghz, 1giga di ram.
ipod nano 4giga and ipod hifi ed ora anche ipod video 30giga white
User avatar
LordSteve
Nume Tutelare di Mac Peer
Posts: 1803
Joined: Sun Apr 16, 2006 11:45 pm

Post by LordSteve »

User avatar
iGodness
Pietra Miliare di Mac Peer
Posts: 1338
Joined: Mon Feb 13, 2006 3:07 am

Post by iGodness »

Security Update 2007-006

What's New

WebCore

CVE-ID: CVE-2007-2401

Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.9 or later, Mac OS X Server v10.4.9 or later

Impact: Visiting a malicious website may allow cross-site requests

Description: An HTTP injection issue exists in XMLHttpRequest when serializing headers into an HTTP request. By enticing a user to visit a maliciously crafted web page, an attacker could conduct cross-site scripting attacks. This update addresses the issue by performing additional validation of header parameters. Credit to Richard Moore of Westpoint Ltd. for reporting this issue.

WebKit

CVE-ID: CVE-2007-2399

Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.9 or later, Mac OS X Server v10.4.9 or later

Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution

Description: An invalid type conversion when rendering frame sets could lead to memory corruption. Visiting a maliciously crafted web page may lead to an unexpected application termination or arbitrary code execution. Credit to Rhys Kidd of Westnet for reporting this issue.

This document describes Security Update 2007-006, which can be downloaded and installed via Software Update preferences, or from Apple Downloads.
User avatar
simulacron
Mac Peer Aficionado
Posts: 335
Joined: Sun Dec 04, 2005 8:28 pm

Post by simulacron »

Scaricato l'aggiornamento 2007-6....... 8) 8)
"Considerate la vostra semenza:
fatti non foste a viver come bruti,
ma per seguir virtute e canoscenza"
Ulisse a Dante (Inferno,Divina Commedia)

Post Reply