MacDailyNews - Where Mac news comes first

 MacDailyNews Poll

Deal of the Day

5 Day Most Commented

Opinion Archive

Current Headlines

Latest Joy of Tech

  • Latest Joy of Tech!

MacNN

AppleInsider

Macworld UK

TUAW

MacRumors

Yahoo! Finance AAPL

iTunes Top 10 Albums

Mac OS X Downloads

Sat, Nov 21, 2009 - 10:04 AM EST  —  AAPL: 199.92 (-0.59, -0.29%)  |  NASDAQ: 2146.04 (-10.78, -0.5%)

Apple releases Security Update 2007-009
Monday, December 17, 2007 - 04:26 PM EST

Apple today released Security Update 2007-009 which is recommended for all users and improves the security of the following components:

- Core Foundation
- CUPS
- Flash Player Plug-in
- Launch Services
- perl
- python
- Quick Look
- ruby
- Safari
- Samba
- Shockwave Plug-in
- Spin Tracer

Security Update 2007-009 is available via Software Update and also as standalone installers.

More info and download links:
Security Update 2007-009 (10.5.1) - 35.6MB
Security Update 2007-009 (10.4.11 Universal) - 27.4MB
Security Update 2007-009 (10.4.11 PPC) - 15.9MB

Bookmark and Share

Always -- Free ground shipping with orders over $50 at the Apple Store.

Reader Feedback: = registered.
Unregistered users: Feedback from multiple usernames are subject to deletion. Off-topic and posts from suspected astroturfers will be removed.

Dec 17, 07 - 04:35 pm Comment from: Makk

Flash player plug-in?

Dec 17, 07 - 04:40 pm Comment from: peaPod

I feel safer already.

Dec 17, 07 - 04:40 pm Comment from: Jackson R. Lewis

Hey, MDN please explain why this is necessary. There are not suppose to be any security issues with Macs or OSX or anything Apple. With your reassurance, I'll continue to ignore these unnecessary notices. Thanks.

Dec 17, 07 - 04:51 pm Comment from: TJ Draper

Jackson R. Lewis please note...

Apple's are not invulnerable, and I do not believe MDN argues such. However, OS X is the currently the most secure platform. Security updates would still be necessary as vulnerabilities are discovered. This still doesn't change the fact that it is the most secure platform.

Dec 17, 07 - 04:53 pm Comment from: loopy_nj

@Jackson Lewis

There is a HUGE difference between pro-active security updates versus an exploit that is already "in the wild". The Mac difference is that the OS gets patched before the problem begins to be exploited and there are far FEWER of them.

Dec 17, 07 - 04:55 pm Comment from: Zune Tang®

Another day, another security update from Cupertino to patch their 30-year old dinosaur OS. Reminds me of the guy down the street who somehow keeps his '77 Chevy Monza running. These patches are like the primer he uses on the rust spots. Wish he'd do something about the stinky exhaust.

When will Apple get it right? If you MAC lemmings want the latest in a superfast, fantastic looking and solidly secure OS look no further than Magnificent Windows Vista. This Vista thing doesn't need any patches.

Dec 17, 07 - 05:02 pm Comment from: Zune Tang®

I almost forgot:

Your potential. Our passion.™

Dec 17, 07 - 05:05 pm Comment from: Rob

Getting sloppy Zune Tang, just like your hero, M$

Dec 17, 07 - 05:08 pm Comment from: Haiku

Wish he'd do something about the stinky exhaust.

who'd'a ever thought
the great and terrible "Zune"--
turns out she's a chick!

Dec 17, 07 - 05:11 pm Comment from: Justin P. Reese

Apple has third party companies like Symantec to search out vulnerabilities. One was recently discovered in Quicktime Player, where an outside source (if the firewall was turned off) could execute arbitrary code on the Mac.

These updates are necessary.

Dec 17, 07 - 05:12 pm Comment from: Yours Smugly

My MacBook's security is now snappier. Whatever that means.

Dec 17, 07 - 05:24 pm Comment from: shmack

my MBP is now flashier than before.

Dec 17, 07 - 05:29 pm Comment from: farmertomato

Hey, silly rabbits--
These updates are the reason why Macs don't have security problems.

Dec 17, 07 - 05:45 pm Comment from: Greg L

It’s not for ALL users, it’s for all users of 10.4 or 10.5. OS X 10.3 isn’t covered.

Dec 17, 07 - 05:51 pm Comment from: TowerTone

OOh, good. Now I can take that condom off.

And BTW, a 77 Chevy Monza? My God, I had forgotten they even existed!

Dec 17, 07 - 05:58 pm Comment from: bob

If there is one thing that can spoil a good discussion at MDN it is the useless and boring Zune Tang ... Zune great cut and paste posts ... same ole same ole ... go away ...

Dec 17, 07 - 06:03 pm Comment from: Shogun

I second Bob's emotion!

Dec 17, 07 - 06:08 pm Comment from: LorD1776

If I remember correctly, Chevy stuffed a V8 into some of those Monzas. You had to unbolt the motor mounts and jack up the engine to change the spark plugs. American engineering at it's finest.

Dec 17, 07 - 06:24 pm Comment from: Jubei

It's nice to know that Apple at least notifies you of updates. Unlike Zune Tongued in the Butts favorite company, there are no updates installed behind your backs. Those MS guys sure love sticking their codes in behind your computers "back doors". Although it makes ZTITB all squirmy and happy inside. wink

Dec 17, 07 - 06:26 pm Comment from: Regular Reader

Zune Tang, do you wanna know what you can do with your Vista? smile

Dec 17, 07 - 06:58 pm Comment from: Realist

I agree. What a joke.

Dec 17, 07 - 07:13 pm Comment from: Realist Dope

Macs suck. They are insecure, like their users.

Blah de blah...

Dec 17, 07 - 07:30 pm Comment from: LordRobin

Well, at least thanks to registration, there's only ONE Zune Tang, instead of dozens of idiots pretending to be him, just like Sputnik before him.

Dec 17, 07 - 07:35 pm Comment from: NeonRed

Isn't Vista still a DOS program? When you build a good base for the OS you can milk...er use it for 30 years.
-- m$... we don't have the time to breed a new OS---
Transplants and resuscitations are the way to the
money...
Works for m$ i guess.

Dec 17, 07 - 08:05 pm Comment from: YoYo

Zune Tang! Leave my '77 Chevy Monza alone othervise I'll tell everybody that underneath your new black Ford F150 skin is actually a pink -79 International Harvester Scout II. And fix those damn brakes, they squeal like a pig in heat.

Dec 17, 07 - 08:10 pm Comment from: RickS

The comments on this site are strange!

Dec 17, 07 - 08:11 pm Comment from: Vista is NT

Thy basically Killed off DOS with Windows ME (or XP) . The DOS base was being replaced with Win32 code in 98 and ME, while they were working on their (separately purchased) NT server stuff. they basically rolled out XP as "Windows, when it was actually NT. Same With Vista.

Just as Apple Took OS 7 Out back and shot it finally when OS X was released, they had to limp along on their old code, updating it to OS 8 and OS 9, while they prepped their New OS - OpenStep - they got when they bought NeXT. They slowly rebranded The server and the client with the SAME OS (after some initial frustrations) - MacOS X - While MS decided to keep them separate until XP. MS also keeps different versions of the code separate (32 / 64) so there are differences there too....

SO with 2 core OSes in transition, and each with different builds and codebases, - even when they finally "simplified" to having 3 or 4 base ones (with Win CE) - Look at what vista turned into. Apple has one base - OS X - That powers their desktops and servers, the same code made to compile for 2 different CPU's (the intel's & PPC's) and a client and server version. And it even runs on ARM processors for the iPods and iPhones.

There is no magic solution - for MS to come in and buy a Newer OS to replace their messy base code, nor does anyone seem to have the guts to take anything out back any more and shoot it - and finally write their crap again from the ground up and make it modern - or base it on open source and make the interface private, Like Apple does.

they painted themselves into a corner, and it's gonna be fun to watch them try to get out of it. I bet they're gonna have to walk through their paint eventually.

A lot of the info I got was reading the history stuff from RoughlyDrafted(dot)com - Daniel seems pretty good at telling the tail of the OSes and the people involved.

Dec 17, 07 - 09:13 pm Comment from: LorD1776

RickS,
The comments are nothing compared to the people. We're a bunch of freaks. Well, at least I am. Was that a strange comment?

Dec 17, 07 - 09:23 pm Comment from: Unregistered

Well, glad to see these got patched. Some were pretty serious:

CFNetwork
Desktop Services
GNU Tar
Launch Services - Description: Launch Services does not handle HTML files as potentially unsafe content.
Quick Look (both)
Safari (both)
Software Update

Those were the main ones that stuck out to me, but, alas, they are fixed.

Dec 17, 07 - 10:00 pm Comment from: iamdj

Yeah, but is it a "snappy" feeling security update?

Dec 17, 07 - 10:01 pm Comment from: Jubei

The patch for the Flash plug in is pretty important. Flash has been making Safari quite unstable since the release of 10.5. Glad that is fixed.... I hope.

Dec 17, 07 - 10:04 pm Comment from: eric

We aussie are pretty dumb sometimes

http://www.smh.com.au/news/technology/the-ipod-speaker-that-comes-with-builtin-tuna/2007/12/15/1197568324984.html

Dec 17, 07 - 10:12 pm Comment from: clunker

Hey, MDN please explain why this is necessary. There are not suppose to be any security issues with Macs or OSX or anything Apple.

It's the same reason even the best automakers issue service bulletins, recall vehicles, and have parts & service departments at their dealerships.

For problems, it's a question of how many, how serious, and how proactive vs. reactive. Are we dealing with cup holders that might rattle, or widespread total brake failures? Are new-style locks issued as a precaution, or an urgent response because everyone's car is getting stolen?

We shouldn't have to point out the parallels to which OS...

Dec 17, 07 - 10:14 pm Comment from: dk

Anyone else notice their spotlight not working or the search dialog not even showing up after the update?

Dec 17, 07 - 11:16 pm Comment from: @YoYo

Damn funny... thx

jay

Dec 17, 07 - 11:50 pm Comment from: Pete

Don't install Leopard, it's a mess.

A little Cupertino bird told me.

Dec 18, 07 - 01:49 am Comment from: koolau

"The comments on this site are strange!"

I like reading the comments more than the articles smile

Lots of creative people here...

Dec 18, 07 - 03:21 am Comment from: Bartsimpsonhead

"The comments on this site are strange!"

As the Doors sang:
People are strange when you're a stranger
Faces look ugly when you're alone
Women seem wicked when you're unwanted
Streets are uneven when you're down


or as I like to sing:
Leopard seems strange when you're a stranger (to it)
And Vista look's ugly because it's a clone
ZuneTang seems wicked when she is babbling
She's only jealous Vista's fulla holes

Dec 18, 07 - 04:41 am Comment from: Walter Chillum

Ah Sputnik,

I remember him/her well.

WC

Dec 18, 07 - 05:48 am Comment from: HaHaHaHa

"The Mac difference is that the OS gets patched before the problem begins to be exploited and there are far FEWER of them."

That's for sure. there are far fewer Macs. So few in fact that any Macs you encounter in the wild are probably a figment of your imagination.

Dec 18, 07 - 07:30 am Comment from: British Mac Head

@Bartsimpsonhead

Love the sing dude.

And yes, I too believe Zune Tang is a woman and a Mac user with a sadistic streak that wants to get us all riled up. I have asked MDN to think about an icon that shows either an Apple, a Tux icon or a Doze logo next to each post so we can recognise people who are just on here to have a laugh from the real Windows zealots. What do you reckon guys? Good idea or what?

I'm guessing the real Mac Heads and Real Windows users will like this idea while the impostors won't. We'll see!!!

Dec 18, 07 - 07:31 am Comment from: British Mac Head

That should have been "love the song dude"
D'oh!

Dec 18, 07 - 07:52 am Comment from: ping

dk: Anyone else notice their spotlight not working or the search dialog not even showing up after the update?

Nope. Still works normally here. On both Tiger and Leopard.

Dec 18, 07 - 09:40 am Comment from: Ampar

" . . . any Macs you encounter in the wild . . ."

Well, safari, so good. And why there was an elephant in my pajamas I'll never know.

Dec 18, 07 - 10:22 am Comment from: silverhawk

My MPB 15" (late 2006 model) had trouble rebooting after this one. Actually I got tired of waiting for the spinning wheel and went to bed. Six hours later my wife found it and shut down the computer. When I awoke I pushed the power button and it's working.

Dec 18, 07 - 10:45 am Comment from: Maceral

I did the update. Now I'm in a setup assistant loop. It shows my old log in icon and every time I log in it goes back to setup assistant and asks for my info again. I can't log out or exit. Anyone else have similar issues?

Dec 18, 07 - 11:10 am Comment from: Ampar

Here are the step if you get caught in the Leopard Setup Assistant Loop Bug:

1) Boot into Safe Mode by holding down the shift key upon boot.
2) Do not login.
3) Hit the back arrow key.
4) Then, hit the restart button.
5) It will then rerun the updates.
6) Wait until the process is complete and it will finally restart.

Dec 18, 07 - 11:17 am Comment from: Ampar

Should be, "Here are the steps . . ."

Unintended anti-pluralism.

Dec 18, 07 - 11:32 am Comment from: Yaardvark

Nothing for 10.3.9? Does this mean Apple is done supporting my system and I need to upgrade if I want to continue to use it to browse the web?

Dec 18, 07 - 01:06 pm Comment from: Ampar

Yaardvark:

Re: Panther Security

You might find answers here:
http://www.apple.com/support/security/

Or here:
http://discussions.apple.com/category.jspa?categoryID=161

Dec 19, 07 - 09:07 am Comment from: Cousar

My MacBook completed the download and install, but the battery died before it could restart. Now the LED on the charger plug alternately blinks orange and green. What should I do?

Reader feedback page 1 of 1 pages:

Always -- Free ground shipping with orders over $50 at the Apple Store.

Add Your Feedback:

Register or Login

Name:

Email: (optional)

Emoticons | Allowed HTML Tags

Remember my info   Notify me of follow-up comments?

Please enter the "MDN Magic Word" you see in the image below: