Follow Us

Apple patches 36 bugs in Mac OS X Lion and Snow Leopard

Updates Lion to 10.7.4, provides security-only fixes for Snow Leopard

Apple has patched 36 vulnerabilities in Mac OS X Lion and Snow Leopard, most of them critical, plugging a hole that revealed passwords used to encrypt folders with an older version of FileVault.

Both Mac OS X 10.7 Lion, and 10.6 Snow Leopard were updated with fixes. The two operating systems were last updated in February.

High on the fix list was one specific to Lion that put FileVault passwords in plain text, where they could easily be read - and thus encrypted folders deciphered - if a Mac was stolen or lost. The software consultant who publicly reported the bug attributed it to a programming error on Apple's part.

"The login process recorded sensitive information in the system log, where other users of the system could read it," Apple's advisory stated. Apple also acknowledged that the plain-text passwords may persist in the Mac's logs after users update to 10.7.4, and urged them to review a support document that walked through steps to eradicate any that are remaining.

Among the other patches were four Snow Leopard-only fixes quashing bugs that could be exploited via malicious image files; another four in QuickTime, Apple's media player and browser plug-in; and one in FileVault 2, the full-disk encryption technology used by Lion.

The FileVault 2 flaw caused some date to be left unencrypted when a Mac went into "sleep" mode.

Twenty-one of the 36 vulnerabilities were tagged with Apple's phrase of "arbitrary code execution," indicating that they were critical flaws that, if exploited by attackers, could result in a Mac malware infection.

Eight of the bugs affected only Snow Leopard.

On Lion, Apple also included a number of non-security fixes it categorised as stability and compatibility improvements. Many of them were related to connecting to network services, such as Microsoft's Active Directory and that company's Server Message Block (SMB) file-sharing protocol. Both are used by Macs in enterprises to access corporate resources held on servers running Windows.

Snow Leopard's update, dubbed "Security Update 201-002," received no feature improvements.

Yesterday's update may be the last for Snow Leopard, as Apple seems to be on the fast track for OS X 10.8, aka Mountain Lion, which may ship as soon as late June. Apple typically stops serving security updates to the oldest edition in its support rotation when it finalises a major operating system upgrade.

Last year, OS X 10.5, or Leopard, received its final security update in late June, about a month before Apple launched Lion. Leopard's versions of iTunes, QuickTime and Java, however, were updated after June 2011.

As usual, some users reported problems with the update.

On the Lion support forum, complaints ranged from kernel errors and difficulty reaching a Wi-Fi network to numerous reports of bricked MacBook Pros.

No one problem was dominant in those reports, but the MacBook Pro-not-booting thread was heavily trafficked.

Mac OS X 10.7.4 and the separate 2012-002 security update for Snow Leopard can be downloaded from Apple's support site or installed using the operating system's built-in update service.




Comments



Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Optimise Performance For Global eCommerce

Global is all the rage: eBusiness teams are feverishly building new international initiatives in...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Techworld UK - Technology - Business

Part 2 of your journey to virtualisation

You can still access part 2 of our virtualisation journey - explore how you can improve your servers, storage and networks by developing your infrastructure.

Watch now...
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *