Mac Security: Security Update 2007-007

Discussion started by Derek Currie, Aug 1, 2007.

  1. Derek Currie

    Derek Currie Guest

    On Tuesday Apple released Security Update 2007-007. It is a large
    update including 25 security vulnerability patches. You can read
    about the update at:


    You can download the update via your Mac OS X Software Update
    system preference pane of download it from:


    Here is a brief list of items patched by this security update:

    Quartz Composer

    Note the mDNSResponder patch. It will be interesting to see if
    this repairs the rumored (as yet unproven) hole in mDNSResponder
    reported last week.

    * As ever, before you install any major update it is important
    for first:
    (A) Repair your boot volume's permissions using DiskUtility.
    (B) Verify your boot volume using DiskUtility, and if problems
    are evident it is critical that you repair them either by booting
    from your Mac OS X installation disk, then using DiskUtility to
    perform the repair, OR install AppleJack then run it while booted
    in Single User Mode.

    Why bother with this? The vast majority of problems that result
    from performing updates are due to pre-existing problems on

    AND, after running an update it is very useful to again repair
    your permissions and again verify your boot volume. Apple have
    been very good lately about cleaning up permissions after their
    updates. But some companies, notoriously Adobe, leave behind a
    mess after their installers or updaters run.


    1) AirPort Extreme Update 2007-004:
    2) Safari 3.0.3 Public Beta

    Share and Enjoy,


    Fortune Magazine 11-29-05: What's your computer setup today?
    Frederick Brooks: I happily use a Macintosh. It's not been
    equalled for ease of use, and I want my computer to be a tool,
    not a challenge.
    [Frederick Brooks is the author of 'The Mythical Man Month'.
    He spearheaded the movement to modernize computer software
    engineering in 1975.]
    Derek Currie, Aug 1, 2007
  2. Derek Currie

    Peter Hayes Guest

    Peter Hayes, Aug 1, 2007
  3. I think they just fall into a generic class of buggy programs that MAY
    if you send a few years concocting just the right shape of archive,
    scribble on their stacks and cause 'interesting' behaviour..

    Mostly they will just crash though.

    The original Internet worm exploited just such an issue.

    It depended on one operating system (Ultrix IIRC), one particular
    compilation of sendmail and one type of hardware..but that was
    ubiquitous enough to crash half the internet.

    Stack underflow is an ever present risk. As long as processors have
    program and data stacks in the same place, and compilers use that stack
    for temporary data areas..and programmers continue to use unchecked data
    sizes into fixed sized buffers...
    The Natural Philosopher, Aug 2, 2007
