Apple releases Security Update 2007-004

Apple today released Security Update 2007-004 which is recommended for all users and improves the security of the following components:

• AFP Client
• AirPort
• CarbonCore
• diskdev_cmds
• fetchmail
• ftpd
• gnutar
• Help Viewer
• HID Family
• Installer
• Kerberos
• Libinfo
• Login Window
• network_cmds
• SMB
• System Configuration
• URLMount
• Video Conference
• WebDAV

More info and download links:
• Security Update 2007-004 (10.3.9 Server) – 54.1MB
• Security Update 2007-004 (10.3.9 Client) – 37.6MB
• Security Update 2007-004 (PPC) – 9.3MB
• Security Update 2007-004 (Universal) – 16.1MB

Security Update 2007-004 is available via Software Update.

45 Comments

  1. “Nowadays, security guys break the Mac every single day. Every single day, they come out with a total exploit, your machine can be taken over totally. I dare anybody to do that once a month on the Windows machine.” — Bill Gates

    I sure hope Bill Gates is totally wrong here, I see too many of these security updates lately.

    Thankfully OS X market share isn’t such a big target as Windows is.

    (yea I know, I disagree)

  2. Difference is, Apple gets these updates out BEFORE these issues ever impact anyone out in the wild. Too bad M$ can’t say the same.

    No Mac in the wild has ever been “taken over totally” anyway, Bill Gates is full of sh*t (and FUD) as usual….

  3. Oh one more thing…

    For true security, you need to:

    1: Backup files, disconnect other drives.

    2: C boot from Mac OS X disk

    3: Select Disk Utility and Erase w/Zero your boot drive.

    4: Install Mac OS X, change your passwords, and immediately Software Update to the present version. (with wired connection to internet)

    5: Enable Firewall advanced options especially Stealth mode.

    6: Install apps from original sources and immediately update.

    7: Avoid apps that demand a admin password to install. 95% of exploits are application exploits. Refusing admin password limits the “hooks” and exploit potential of Mac OS X considerably.

    8: Clone your new boot config to a Zeroed external hard drive and keep seperate. Use this clone only when no other drives, including the boot drive (unless Zeroed first while C booted from a OS X boot DVD) are physically attached to the computer.

    This way nothing can “jump” over to your pristine clone.

    9: Never use your real name when registering Mac OS X, Apple puts your name everywhere.

    10: Use low level debit cards online and transfer cash from a low amount savings account.

    11: Practice “compartmentalized security” to substancially reduce risk.

    Of course there is the slight possibility your machine could be exploited remotely before the OS loads the new security updates. So wireless is definably not the way to go during this crucial period.

    It’s best to get new OS update on a disk from a secure source before doing above.

    Just because there isn’t any “OS X malware in the wild” doesn’t mean someone doesn’t have a hard on for your box.

    Don’t get me started about EFI, this is a totally unprotected powerful firmware environment.

  4. Everything you’ve said here makes sense on paper, but the reality is that OS X has been around for nearly 6 years and still has no malware. OS 7, 8, and 9 combined were around for 6 years, and EACH of them had viruses. They also had fewer users.

    Have you checked out the new malware for iPods with Linux installed on them? How many iPods do you think have Linux installed? 200? 300? A thousand? How many non-Linux iPods are there? Over a hundred million. How many viruses for them? None.

  5. Difference is, Apple gets these updates out BEFORE these issues ever impact anyone out in the wild. Too bad M$ can’t say the same.

    Right, but if Apple had the market share of Windows, the opposite would be true.

    In the Windows world, as soon as a exploit is public, it’s exploited to hell and back with hours.

    Apple has had critical exploits that went unfixed for several months and nobody really bothered.

    Why is that? Small OS X market share is the only answer.

    No Mac in the wild has ever been “taken over totally” anyway, Bill Gates is full of sh*t (and FUD) as usual….

    Of course, but he did say “can”.

    Rememeber Apple didnt fix the URL Handler exploits of Panther for several months. It was posted on Slashdot and every hacker had seen it but nobody really made any use of it.

    No botnets or viruses or anything. Why?

    Market share. It’s really hard to find a Mac OS X box out there amongst all the IP addresses of Windows machines.

    That’s what has been protecting us.

    Beleive it.

  6. Its great that Apple is paying attention to security issues. As long as humans write code, especially millions of lines of code, there will always be some sort of bugs that can lead to exploits.

    Apple keep the patches coming….

  7. According to Appleinsider, this is most of what the security patch is fixing.

    For the most part, the vulnerabilities addressed by the Mac maker’s latest security update could translate into denial of service attack, unexpected application termination, or arbitrary code execution. However, Apple made note of several more critical issues that could allow malicious users to gain elevated system privileges through AFP Client, Airport, CarbonCore, Kerberos, WebDav and the Mac OS X Login Window.

    The Cupertino-based company also addressed two other significant shortcomings of the Login Window. The first, resulting from insufficient checks of environmental variables, could allow local user to obtain system privileges and execute arbitrary code. The other, meanwhile, would at times allow the screen saver authentication dialog to be bypassed without entering a password even when a user had set his or her preference to “require a password to wake the computer from sleep.”

  8. WiseGuy – If I thought I had to do all that just to feel free to surf the net, I’d find another line of work or hobby. You must have come from the Windows world, where you had bad experiences every other day. I’m content to allow the inherent security of OSX protect me rather than to become paranoid about computer security. You’re making computering sound like not much fun.

    And you’re so wrong about the reason there haven’t been any Mac exploits. Sure, they only have 5% market share (and much higher installed base), but with all the shouting going on about Mac security you don’t think that some hacker somewhere wouldn’t just love to be the first to hack a Mac? Some guys even went so far as to fake it. Remember that not long ago, about the “hacked” wi-fi? Only it wasn’t Mac software. If it could be done easily it would have been. Count on it.

  9. lol wiseguy….

    you see too many security updates soo you are worried that machines will get hacked? why? because they are staying ahead of the break ins? oh my god no!

    …if you stop seeing updates BEFORE the vulnerability, then you can get worried.

    and that is just the first line. don’t get me started on your often disproved and mindless security through obscurity or you paranoid tinfoil hat wearing steps to take for an update!

    again, for the nth time i ask, why is it every message board has someone using names with “reality” and “wise” and “informed” in them, and they are ALWAYS the least intelligent, most divorced from reality posters on the board?

    one of life’s great mysteries.

    magic word, “efforts” as in your efforts at FUD are for naught.

  10. @Ballonknot

    Just because Unix has been around doesn’t mean it’s secure. Just look at this chart.

    http://blogs.technet.com/photos/tsimages/images/471076/original.aspx

    It seems the “popular OS” that touts “security above all others” all of a sudden begins to have more and more exploits.

    Linux used to be the “security” OS. “More eyes looking at the code” was the supposed reason for Linux security and advocatation for open source.

    Mac OS X used to tout “Unix security” and now both Linux and Mac OS X are trending upwards in exploits. Why?

    Unix is trending downwards because a lot of Unix installations are being replaced by Windows Server.

    Windows is actually trending downwards, which is hard to beleive. Unfortunatly for Windows large market share, a single exploit can mushroom overnight.

    Mac OS X doesn’t have that problem.

  11. @ WiseGuy:
    Where’s the wise hint not to use an admin, but a standard user?
    I missed that one in the list.

    And beside of that:
    Updates being published before a thread is known, scare me, too.
    Or is time travel indeed possible? I’d guess that’s where the secret
    10.5 features come from… Does Apple copy future M$ products…?
    Sorry, drifted away a bit now… ” width=”19″ height=”19″ alt=”wink” style=”border:0;” />

  12. WiseGuy said: “Beleive it.”

    :o)

    There is a flaw in your argument. The hacker who successfully attacks OS X will get a rep ten miles long. Look at the publicity a Linux iPod exploit (where you had to actually install the “virus”) received.

  13. The hacker who successfully attacks OS X will get a rep ten miles long

    LMH’s and Kevin Finisterre’s are right past the 10 mile mark.

    LMH said that while his upcoming project had the potential to at least temporarily make security more tenuous for the average Mac user, he believes that in the long run the project will improve OS X security.

    “Right now, many OS X users still think their system is bulletproof, and some people are interested on making it look that way,” LMH said.

    http://blog.washingtonpost.com/securityfix/2006/12/january_2007_month_of_apple_bu.html

  14. There have been a troubling number of Mac security updates lately. I will feel much better once they release Leopard, and have all the latest Mac OS X security by default.

    @ Wiseguy “In the Windows world, as soon as a exploit is public, it’s exploited to hell and back with hours.
    Apple has had critical exploits that went unfixed for several months and nobody really bothered.
    Why is that? Small OS X market share is the only answer.”

    There IS more then one explanation: even with potential security holes, Mac OS X still has multiple layers of security that would make a destructive program near impossible. A theoretical Mac OS X virus has many hurdles to leap over, such as administrative access requiring a password, that root access is disabled by default, that Safari web browser does not allow web scripts to modify system files, etc.

    The difference between Mac OS X security and Windows security is simple: one is brilliantly engineered, the other is broken patchwork.

    Any idiot who knows a little javascript can read the details of an unpatched windows vulnerability and create a trojan.

    On the flip side, a computer hacker, who has all the details of Mac security flaw, would still face an enormous challenge developing a Mac virus to full fruition, a challenge so near impossible that success would be an unprecedented achievement of master hackery.

    @ Wiseguy, again, about that huge list of security precautions: you remind me of me back when I still used Windows, except slightly more paranoid. But at least I had an excuse, having spent hours battling viruses and spyware, mostly on other people’s computers. Experience as the resident tech guy has taught me a lot: Windows malware is a fearsome monster, never to be underestimated, always shrouded in deception, that often cannot be destroyed without formatting the entire OS. I sleep much better now that I own a Mac.

  15. LMH’s and Kevin Finisterre’s reputations are in ruins because they couldn’t back up what they claimed.

    They, like WiseGuy, confuse flaws with vulnerabilities and vulnerabilities with exploits. The reality is that no OS (or anything else!) is without flaws, but not all flaws are vulnerabilities. Most flaws aren’t! Likewise, not all vulnerabilities can be exploited to the point that they become real threats.

    Windows users like WiseGuy have trouble understanding this because in Windows many flaws are vulnerabilities, and many vulnerabilities are easily exploited. That’s what happens when you start out with a poorly written OS and then insist on retaining backwards compatibility with lousy software written decades ago!

    The plain truth is that there are lots of people who would love to create an exploit for the Mac, and they’ve been trying for years. There’s only one reason they haven’t been successful and it’s got nothing to do with market share.

  16. @WiseGuy

    I appreciate your attention to security…but I caution you on confusing vulnerabilities with exploits.

    The numbers of vulnerabilities for Unix, Linux, and Mac OS X, Have been increasing while for Windows they have been decreasing.

    An open system should have more discovered vulnerabilites than a closed system like Windows.

    This actually has a positive effect of discovering and fixing the vulnerabilities quicker, thus causing the the OS to become more secure over time.

    This is the way you want it to work. More vulnerabilities discovered are much better than more vulnerabilities hidden.

    When they are hidden like the ones in Windows…attackers don’t publish them, they use them in secret for their benefit. Zero Day exploits can fetch a lot of money on the underground market.

    Again…Vulnerabilities do not equal exploits.

  17. @Wiseguy

    You obviously came from Window$ world to be that paranoid. Keep floating that security via obscurity myth and maybe just maybe some ignoramus will believe you.

    A single Mac exploit will definitely earn someone reps more than you’re trying to get. But then no one’s really broken and taken over a Mac or have you?

    Makes me wonder what happened to the CanSecWest contest where they’re giving away 2 loaded and souped up MacBook Pros to those who can break in them. The 3day grace period is almost over. I haven’t heard anybody break one as of this posting. I can hear them say, “Gents, prepare your speeches in order to get these MBPros.” hehehe.

    Anybody who believes this Security via Obscurity is just as flawed as microsuck.

  18. Just as I was about to post that.

    I wished they’ve given more time for the guys to try to break in. Just to prove a point.

    Otoh, OS X has been out there years already and no exploits so far. Compared that to the supposed-to-be-WOW-that-turned-WEH Microsoft OS that is Vista.

  19. @WiseGuy

    25 flaws this time, compared to the tens of thousands of exploits/viruses/what have you for Winblows. Gee, I think I’ll take my chances, thanks…

    Why don’t we just settle this: ALL computers, no matter how secure any of them claim to be (Macs with OSX included), WILL have security flaws which need to be patched. That’s just the way it is, and the way it will always be.

  20. Be wary of this security update. Many users on the apple discussion forum have reported that this security update resulted in the corruption of iCal and/or iSync applications. I haven’t been able to get iSync to sync my calendar to my dot mac account since I installed this update. And iCal unexpectedly quits immediately after opening it and that started immediately after installing this security update. If anyone can offer any help to get iSync and iCal up and running again I’d be grateful for an e-mail.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.