Security - Channel Insider
Empowering the next generation Channel
 

Sponsored Links
  • Try Windows Azure free for 90 days

  • Introducing the world's first family of systems with integrated expertise

  • FREE Securing Smartphones & Tablets for Dummies Book from Sophos
  • 5 New Technologies That Will Change Enterprise ITAdvertisement
  • Build an IT Infrastructure That Delivers the Future

  •  

    Apple Launches iOS 5, iCloud, Fixes for Mac OS X, i Tunes

    in Security



    Article Rating:starstarstarstarstar / 3
    Article Views: 4610

    Apple servers were slammed as users attempted to download updates to iTunes, Mac OS X 10.7.2 and iOS 5 that contain many security fixes.

    Rate This Article:
    Add This Article To:

    Coinciding with the launch of its new iCloud service, Apple has rolled out massive updates fixing scores of security vulnerabilities in Mac OS X, iOS and related software.

    The latest mobile operating system, iOS 5, went live Oct. 12, which requires the latest version of iTunes to install. Apple released a new version of its iTunes software for Windows on Oct. 11. If those two major upgrades weren't enough, Apple also updated the Mac OS X Lion operating system with 10.7.2. A security update for Snow Leopard users, 10.6, is also available.

    Users trying to access so many updates so close together are putting a strain on Apple servers, resulting in long download times and strange error messages when trying to install, according to irate users on Twitter and Apple support forums.

    The upgrades are necessary for users interested in using iCloud to synchronize music, photos, documents and other files across their iPhone, iPad or iPod Touch and the Mac desktop. The latest iTunes, version 10.5, is necessary to upgrade to newer models of the iPhone, iPad and iPod Touch to iOS 5. Both the Mac and Windows versions of iTunes have all the features necessary to take advantage of iCloud support, wireless synchronization and iOS 5.

    The iTunes 10.5 for Windows update patched 79 security vulnerabilities in a slew of components, including WebKit, ColorSync, CoreFoundation, CoreAudio, CoreMedia and ImageIO, according to Apple's advisory. WebKit alone accounted for 73 bugs that Apple fixed in this version of iTunes. The framework is a core part of iTunes and the Safari Web browser, and all but one of the bugs were memory corruption vulnerabilities. Several of the bugs, if exploited, could have resulted in an attacker remotely executing code on the affected Mac. Other WebKit issues would have resulted in denial-of-service conditions or crashed iTunes, according to Apple.

    Apple fixed the security issues in iTunes only in the Windows version, and rolled the fixes into the OS X updates for Mac users.

    In the Mac OS X 10.7.2 update and the update for 10.6 (Snow Leopard), Apple fixed 75 known vulnerabilities in the operating system, Chester Wisniewski, senior security adviser at Sophos, told eWEEK. Most could lead to arbitrary code execution, while others could result in denial of service or escalation of privileges, Wisniewski said.

    Apple addressed "quite a few important security issues," including the vulnerabilities with Open Directory that had been introduced this summer with the release of Lion, the latest Mac OS X operating system. The various flaws in Open Directory allowed people to read other users' password hashes, change passwords without having to know the old password and log into the system without a password, according to Wisniewski. The OS X update also fixed how Web cookies are stored and handled so that malicious sites can no longer read information stored on them.


    To read the original eWeek article, click here: Apple Fixes Major Bugs in Mac OS X, iOS 5, iTunes With iCloud Launch




    comments dic


     
     
    >>> More Security Articles          >>> More By Channel Insider Staff
     


     



    channel chatter


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


     


    CHANNEL SPONSORED RESOURCE CENTER
     
     
     
    Start the New Year with business intelligence—it’s a smart move
    Join us on February 1 for an encore rebroadcast at either 5 am or 12 noon EST and discover how business intelligence (BI) supports companies in uncertain business and economic climates. Get expert advice on how to create a strategy that fits your organization's needs and budget and see how quickly it can pay for itself.
    Click Here
     
    Security and Availability Essentials for Running Your Business in the Cloud
    Are you moving to the cloud? Find out what every IT professional should know about security and availability before moving to the cloud. Hear what a security provider’s own CSO has to say.
    Watch Video
    A new algorithm automatically identifies relationships between variables to help reduce researcher prejudice.
    Click HereAdvertisement