Submit a Story!
About the security content of Security Update 2008-004 and Mac OS X 10.5.4
Important: Mention of third-party websites and products is for informational purposes only and constitutes neither an endorsement nor a recommendation. Apple assumes no responsibility with regard to the selection, performance or use of information or products found at third-party websites. Apple ...
Comments
Blog Reactions

Safari RSS vulnerability might reveal your personal data
The Unofficial Apple Weblog (TUAW) — Filed under: SecurityWhen reports of security issues in Apple's Safari browser come over the transom, they get our attention. When they're exploitable in both the Mac and Windows versions of Safari, they get our full and undivided attention. When the person reporting them is Brian Mastenbrook (credited with discovering multiple previous vulnerabilities in Mac OS X)... well, someone shut off that damn klaxon and let us get back to work. In this case, the issue is that a hole in Safari's handling of RSS feeds could allow an attacker (via a ...

Security flaw in Safari's RSS feeds reported
AppleInsider — ... as emails, passwords, or cookies that could be used to gain access to the user's accounts on some web sites." According to Mastenbrook, Mac OS X Leopard users should change their Default RSS reader preference to another feed reader.  Possible solutions include Mail and  NetNewsWire . Safari for Windows users should use a different web browser until the security hole is patched, he said. Mastenbrook has a credible reputation for bug reporting, with  no fewer than four  mentions, by name, in previous Apple release notes.

Related Content
Security Update 2009-004 (Leopard)
support.apple.com 8/12/2009 — Download icon About Security Update 2009-004 (Leopard) Security Update 2009-004 is recommended for all users and improves the security of Mac OS X. Previous security updates have been incorporated into this security update. SHA 1 digest = ...
About the security content of Security Update 2009-001
support.apple.com 2/12/2009 — Release date: Mon, 9 Feb 2009 20:34:00 GMT
Security Update 2009-004 (Tiger Intel)
support.apple.com 8/12/2009 — Download icon About Security Update 2009-004 (Tiger Intel) Security Update 2009-004 is recommended for all users and improves the security of Mac OS X. Previous security updates have been incorporated into this security update. SHA 1 digest = ...
Security Update 2009-004 (Tiger PPC)
support.apple.com 8/12/2009 — Download icon About Security Update 2009-004 (Tiger PPC) Security Update 2009-004 is recommended for all servers and improves the security of Mac OS X. Previous security updates have been incorporated into this security update. SHA 1 digest ...
About the security content of Security Update 2008-008 / Mac OS X v10.5.6
support.apple.com 12/15/2008 — Important: Mention of third-party websites and products is for informational purposes only and constitutes neither an endorsement nor a recommendation. Apple assumes no responsibility with regard to the selection, performance or use of information or ...
Security Update 2009-004 (Server Tiger Universal)
support.apple.com 8/12/2009 — Download icon About Security Update 2009-004 (Server Tiger Universal) Security Update 2009-003 is recommended for all servers and improves the security of Mac OS X. Previous security updates have been incorporated into this security update. SHA 1 ...
Security Update 2009-004 (Server Tiger PPC)
support.apple.com 8/12/2009 — Download icon About Security Update 2009-004 (Server Tiger PPC) Security Update 2009-003 is recommended for all servers and improves the security of Mac OS X. Previous security updates have been incorporated into this security update. SHA 1 digest = ...
About Security Update 2009-004
support.apple.com 8/12/2009 — Release date: Mon, 10 Aug 2009 17:52:00 GMT
About the security content of iPhone OS 3.0 Software Update
support.apple.com 6/18/2009 — Release date: Mon, 15 Jun 2009 18:04:00 GMT
About the security content of Security Update 2009-002 / Mac OS X v10.5.7
support.apple.com 5/11/2009 — Release date: Fri, 24 Apr 2009 22:22:00 GMT