Alert

Apple Mac Products Affected by Multiple Vulnerabilities

Last Revised
Alert Code
SA06-132A

Systems Affected

 
  • Apple Mac OS X version 10.3.9 (Panther) and version 10.4.5 (Tiger)
  • Apple Safari web browser
  • Apple Mail

Previous versions of Mac OS X may also be affected.

 

Overview

 

Mac OS X, Safari web browser, Mail, and other products are affected by multiple vulnerabilites. Apple has released Security Update 2006-003 to address these vulnerabilities, the most serious of which may allow a remote attacker to place and run malicious code on your computer.

Solution

Install an Update

Install Apple Security Update 2006-003 through Apple Update.

Disable "Open 'safe' files after downloading"

For additional protection, disable the option to "Open 'safe' files after downloading," as specified in "Securing Your Web Browser."

 

Description

 

Mac OS X, Safari web browser, Mail, and other products are affected by multiple vulnerabilities. Some of these vulnerabilities could allow an attacker to run malicious programs on your computer.

For more technical information, see US-CERT Technical Alert TA06-132A.


 

References

  • US-CERT Technical Cyber Security Alert TA06-132A - <http://www.us-cert.gov/cas/techalerts/TA06-132A.html>
  • Securing Your Web Browser - <http://www.us-cert.gov/reading_room/securing_browser/#Safari>
  • Apple Security Update 2006-003 - <http://docs.info.apple.com/article.html?artnum=303737>
  • Vulnerability Notes for Apple Security Update 2006-003 - <http://www.kb.cert.org/vuls/byid?searchview&query=apple-2006-003>
  • Mac OS X: Updating your software - <http://docs.info.apple.com/article.html?artnum=106704>


 

.

Revision History

  • May 12, 2006: Initial release
    May 16, 2006: Added Vulnerability Notes reference, fixed feedback link
     

Last updated 

This product is provided subject to this Notification and this Privacy & Use policy.