Contribute  :  Web Resources  :  Past Polls  :  Calendar  :  Advanced Search  :  Site Statistics  :  Software Sales  :  Downloads  
    macweb.ciu10.org CIU10 IT Forum    
 Welcome to macweb.ciu10.org
 Wednesday, September 08 2010 @ 09:10 AM EDT

APPLE-SA-2006-12-19 Security Update 2006-008

   

Mac OS X SecuritySecurity Update 2006-008 is now available and provides a fix for the
following security issue:

QuickTime for Java
Quartz Composer

CVE-ID: CVE-2006-5681

Available for: Mac OS X v10.4.8, Mac OS X Server v10.4.8

Impact: Visiting a malicious web site may lead to information disclosure

Description: Java applets may use QuickTime for Java to obtain the images rendered on screen by embedded QuickTime objects and upload them to the originating web site. When this facility is used in conjunction with Quartz Composer, it becomes possible to capture images that may contain local information. This update addresses the issue by disallowing Quartz Composer compositions in unsigned Java applets. Quartz Composer compositions continue to function locally. Applications and signed Java applets that utilize QuickTime and QuickTime for Java are unaffected. This issue does not affect systems prior to Mac OS X v10.4. It also does not affect the Windows platform. Credit to Geoff Beier for reporting this issue.

Security Update 2006-008 may be obtained from the Software Update pane in System Preferences, or Apple's Software Downloads web site: http://www.apple.com/support/downloads/

For Mac OS X v10.4.8 (PowerPC)
The download file is named: "SecUpd2006-008Ti.dmg"
Its SHA-1 digest is: 32af5ee777a3672117db7b6e9d5c96884c7b6bde

For Mac OS X v10.4.8 (Intel)
The download file is named: "SecUpd2006-008Univ.dmg"
Its SHA-1 digest is: 08f2353b65540d94abf6a0b905442af825318409

This message is signed with Apple's Product Security PGP key,
and details are available at: http://www.apple.com/support/security/pgp/




What's Related

Story Options

 Copyright © 2010 macweb.ciu10.org
 All trademarks and copyrights on this page are owned by their respective owners.
Powered By Geeklog 
Created this page in 0.53 seconds