Security Update Addendum: Apple Java for Mac OS X 10.5
September 9, 2009 by admin

Earlier today we discussed software updates, and I inadvertently omitted a big one – Apple last week released a major update to its Java package for OS X 10.5 Leopard. The update, described here and available for download, addresses a rather large number of Java vulnerabilities, some of which potentially allowed unauthorized privilege elevation by executing code from a malicious website.

Note that this update does NOT apply to Snow Leopard, OS X 10.5.6.

This release updates Java SE 6 to version 1.6.0_15 (for 64-bit Intel Macs only), J2SE 5.0 to version 1.5.0_20 (all Intel and PPC Macs), and J2SE 1.4.2 to 1.4.2_22 (all Intel and PPC Macs). The updates catch up with Java fixes released by Sun in August, but apparently there are still a few pending vulnerabilities that have yet to be incorporated into the Leopard packages.

Make sure you update as soon as possible, as there are active exploits in the wild for some of these flaws!

read comments (0)
The Pulse of Security – Are you up to date?
by admin

As you’re reading this, another “Windows Patch Tuesday” has come and gone (Microsoft normally sends their updates on the second Tuesday of the month), and, as is often the case lately, there are some critical security flaws being remedied in this latest round of patches. Do you sometimes feel that this is a never ending battle? Well, in many ways, it is.

Complexity is the enemy of security, and today’s operating systems and the software we employ within them are incredibly complex… breeding grounds for programming errors, which can lead to security flaws.

What’s a poor person to do? How do you keep track of all this churn?

Keep your software up to date automatically, where possible, and check back here on Wednesdays where I’ll be keeping a pulse on the world of software security, and letting you know the straight scoop.

On today’s agenda – Windows monthly update, Snow Leopard introduction, and a summary of browser updates. Let’s start with Microsoft:

(more…)

read comments (0)