Mac OS X update patches 15 security holes

Fixes flaws that could expose your passwords...

NEWS Apple released an update to its Mac OS X operating system on Tuesday to fix 15 security issues in the software.

Many of the problems are flaws in the operating system's underlying open source software, including a critical flaw in the Kerberos authentication system - software that can act as a gatekeeper for computer networks. The patch is available for Mac OS X 10.3.5 and Mac OS X 10.3.4, and also fixes issues in Mac OS X 10.2, known as 'Jaguar'.

A security advisory from the company said: "All security enhancements... are also available for Jaguar, if the issue could occur on Jaguar systems."

The patch fixes software flaws that could enable an attacker to crash or freeze the Apache 2 web server, run software by utilizing Apple's Safari web browser or expose the password store used by the network. Security information provider Secunia/news:link> ranked the Kerberos threat as 'highly critical', its second-highest danger rating.

Apple has pointed to open source software as a source of security for the company's operating system. While open source projects tend to release patches as soon as possible, Apple and other companies have moved to more occasional releases of collections of patches.

Microsoft releases fixes once a month, a move that database software maker Oracle has started to do this month as well.

Apple's advisory, with details of the update, is available on the company's website.

Robert Lemos writes for CNET News.com

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your silicon.com account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy.

Questions about membership? Find the answers in the Membership FAQ

Get silicon.com's daily newsletter

  • Register on silicon.com

    Enter your email to register

Keep in touch with silicon.com

silicon.com newsletters