Apple updates Leopard

And fixes 68 flaws.

More than three months after it last updated Mac OS X, Apple released 10.5.3, an upgrade for its Leopard operating system that boasts nearly 70 stability, compatibility and security improvements and fixes.

Apple did not include patches for several iCal vulnerabilities in the update, however.

Mac OS X 10.5.3, the third upgrade to Leopard since Apple launched it back in October 2007, addresses issues in several components and bundled applications, ranging from the Address Book and Automator to Time Machine and VoiceOver.

Apple also listed a baker's dozen under a "General" category that included a fix for hard drives that wouldn't show in the Finder; an improvement in Spotlight, the OS's built-in search tool, for searches done on AFP volumes; and a patch for stuttering audio and video playback from certain USB-based hardware.

AirPort, Apple's label for its wireless technology, got a pair of fixes: one to improve wireless reliability in general, the other to boost reliability when used with the company's relatively new Time Capsule router-cum-backup-device that debuted earlier this year.

iChat, the Mac OS's bundled instant messaging and video conferencing application, received five fixes; Mail, Apple's own email client, got 10; and Time Machine was the target of seven.

The Time Machine fixes, said Apple, resolve issues when backing up a notebook running on battery power, and address a reliability problem some users have encountered when restoring from a Time Machine backup.

Apple also tucked eight fixes for iCal, its personal scheduling program, into the 10.5.3 update, but did not patch the three security vulnerabilities disclosed a week ago by Core Security Technologies.

The three iCal bugs, which were reported to Apple in January 2008, were revealed last Wednesday by Core after it had repeatedly been asked by Apple to delay publishing its findings. Core decided to unveil the vulnerabilities after Apple again postponed its patches.

"No vendor moves as fast as the vulnerability researcher wants them to," said Andrew Storms, director of security operations at nCircle Network Security.

Storms refused to blame either side. "It generally takes a major vendor, like Microsoft or Apple, about six to eight months to get a patch released," he said. "But Core had every right to push the vendor into delivering the patch."

In a follow-on interview last week, Ivan Arce, Core Technologies' chief technology officer, said that the current version of iCal is vulnerable to the flaws, one of which he considered critical. But his team had not found evidence of any in-the-wild attacks trying to trigger the iCal vulnerabilities.

"It wouldn't take a whole lot of reverse engineering to figure this out," Storms said, referring to the ease with which attackers would be able to put two and two together from Core's disclosures. "It's a valid concern," he added. "The moment you click on a malformed .ics file, you're done."

Apple has not responded to emails asking when it would patch the iCal vulnerabilities.

Mac OS X 10.5.3 can be downloaded manually from the Apple site, or retrieved and installed using Mac OS X's integrated update feature.


What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.


Characters remaining: 500

Related Operating Systems news

Windows 2000, XP SP2, Vista RTM support nears end

Microsoft warns of lapsing support

Windows 7 stability update causes instability

Users face 'blue screen of death' after Microsoft update.

Four in five IT managers do not use cloud technologies

Widespread ignorance about the technology

Microsoft Office 2010 RC released

Release candidate available to invite-only testers



Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Challenges and opportunities of PCI

The Payment Card Industry Data Security Standard provides an enterprise structure for improving operational, security, and audit performance. The benefits of the PCI DSS go beyond audit costs and results.

Download Whitepaper

Database security: Preventing enterprise data leaks at the source

IDC discusses the growing internal threats to business information, the impact of government regulations on the protection of data, and how enterprises must adopt database security best practices...

Download Whitepaper

Six essential steps to successful IT centralisation

This report, based on the real experience of a recent centralisation project, is aimed at those involved in IT strategy within their organisation. It provides some practical insights for CIOs, CTOs, Heads of IT, IT Directors and those involved more closely with the service management function.

Download Whitepaper

Application Grid: The ideal platform for IT consolidation

Evaluating the opportunity for consolidation of middleware — Java application servers and related technologies.

Download Whitepaper

Techworld UK - Technology - Business

COLT White Paper

Are all VoIP services the same?

Questions to ask your service provider to ensure you get the VoIP service you need
With careful choice of partner, your business can have all the advantages of VoIP access - reduced costs, flexibility and simplicity - without the drawbacks.
This white paper is your guide to ensure you get right the VoIP service and details the pitfalls which businesses would do well to avoid.

Download white paper
COLT White Paper

IT Misuse Survey

Complete this survey and you could win a Nexus One

Techworld are running a short survey to discover how UK businesses are managing Internet and email misuse in the Enterprise.

Complete Survey

Webcast: IT Financial Management: Cost Optimisation for Efficiency and Agility.
On Demand Webcast
Join this webcast to learn about the techniques and technologies that can help you prove the value of IT to the business by understanding the true cost of today's IT services and those that will be necessary to deliver future success.

Register Today

Site Map

IDG Network

* *