Submit a Story!
About the security content of Security Update 2009-001
Release date: Mon, 9 Feb 2009 20:34:00 GMT
Security Update 2009-001 (Leopard)
Security Update 2009-001 (Leopard)
support.apple.com — Download icon About Security Update 2009-001 (Leopard) Security Update 2009-001 is recommended for all users and improves... the security of Mac OS X. Previous security updates have been incorporated into this security update. SHA 1 digest = ... (more) Security Update 2009-001 (Leopard)
Security Update 2009-001 (Server Leopard)
Security Update 2009-001 (Server Leopard)
support.apple.com — Download icon About Security Update 2009-001 (Server Leopard) Security Update 2009-001 is recommended for all servers and... improves the security of Mac OS X. Previous security updates have been incorporated into this security update. SHA 1 digest = ... (more) Security Update 2009-001 (Server Leopard)
Security Update 2009-001 (Server Universal)
Security Update 2009-001 (Server Universal)
support.apple.com — Download icon About Security Update 2009-001 (Server Universal) Security Update 2009-001 is recommended for all servers and... improves the security of Mac OS X. Previous security updates have been incorporated into this security update. SHA 1 digest = ... (more) Security Update 2009-001 (Server Universal)
Comments
Blog Reactions

Apple fixes Safari RSS vulnerability, updates Java
AppleInsider — ... in the X11 server, AFP server, Apple Pixlet Video, a memory corruption issue in CarbonCore, and a flaw where local users could access another user's deleted, then recreated, Downloads folder, to name a few. Tiger-specific vulnerabilities repaired with the round of fixes were found in FreeType and LibX11. According to the document, computers running Leopard are either not affected by these two issues or have already been fixed in Mac OS X 10.5.6. Apple Support has the full release notes . Java for Mac OS X 10.5 Update 3, 10.4 Release 8 Leopard users are asked to install Java ...

New OS X Security Update, Java Update available
Infinite Loop — ... . The first security update of 2009 is "recommended for all users and improves the security of Mac OS X." We'll update with a link to the nitty gritty if and when it gets posted to Apple's site, but if you're the adventurous type, you can go ahead and update through Software Update. A restart for the security update is, in typical Apple fashion, necessary. Update: The security document is now up; have fun! ...

Apple releases security, Java updates
The Unofficial Apple Weblog (TUAW) — ... Start your engines -- er, Apple menus -- it's Software Update time! Apple has just issued two security updates today. The first is aimed at Java for OS X 10.5.6 and the Java Web Start and Java Applet components. The second update is for both Mac OS X 10.4.11 and Mac OS X 10.5.6 is a broader security update that addresses the Safari RSS vulnerability we discussed last month, as well as a number of other components (including perl, AFP Server and Remote Apple Events). You'll need to restart your system after installing the security update -- but we ...

Apple releases Mac OS X Security Update 2009-001
MacDailyNews — ... For information on the security content of this update, visit: http://support.apple.com/kb/HT3438

Apple updates Java, OSX Security
9 to 5 Mac - Apple Intelligence — Hit that Software Update to get a comprehensive security updates and some new Java goodness. Security Update 2009-001 AFP Server CVE-ID: CVE-2009-0142 Available for: Mac OS X v10.5.6, Mac OS X Server v10.5.6 Impact: A user with the ability to connect to AFP Server may be a able to trigger a denial of service Description: A race condition in AFP Server may lead to an infinite loop. Enumerating files on an AFP server may lead to a denial of service. This update addresses the ...

Apple Releases Security Updates for Mac OS X, Java for Mac OS X, and Safari for Windows.
TidBITS: Mac News for the Rest of Us — ... Apple has released the first general Mac OS X security update of 2009, patching a series of serious vulnerabilities that could allow an attacker to take over your Mac. Security update 2009-001 affects both Mac OS X client and server, and all users are advised to immediately update their systems. A complete list of changes is found in the official security note on Apple's support site. Apple also released a separate security update for Java for Mac OS X, and a standalone update for Safari for Windows. ...

Security Update 2009-001 fixes Safari vulnerability
MacFixIt — Today's Featured Article Late-Breakers Late-Breakers Thursday, February 12 2009 @ 05:00 PM PST Security Update 2009-001 fixes Safari vulnerability Apple has released Security Update 2009-001, which addresses RSS vulnerabilities in Safari, and problems with CoreText that allow unauthorized execution of code. The update is available in the following editions: A full listing of security refinements for the Leopard edition can be found here . Problems after the update? Please ...

Security Update 2009-001 and Java for Mac OS X 10.5 Update 3
MacCentre701 — ... and Security Update 2009-001 . Java for Mac OS X 10.5 Update 3 includes security and compatibility changes for the Java Web Start and Java Applet components. As for Security Update 2009-001, following components are updated: AFP Server, Apple Pixlet Video, CarbonCore, CFNetwork, Certificate Assistant, ClamAV, CoreText, CUPS, DS Tools, fetchmail, Folder Manager, FSEvents, Network Time, perl, Printing, python, Remote Apple Events, Safari RSS, servermgrd, SMB, SquirrelMail, X11, XTerm. (some software/components listed above are only available to Server version of Mac OS X.) ...

Latest Apple Security Update causes issues with tweaked Perl
Infinite Loop — ... . That security update included fixes for the system default version of the Perl scripting language, which had potential issues when using UTF-8 characters in regular expressions. However, it appears Apple's fixes ...

February Blog Bits: From Safari 4 to iPhone Headsets
The Mac Observer — ... the top of the window to invoke the WindowShade effect. [ADDED: There is a simple way to revert to the old tab behavior: Just enter the following line of text in Terminal: defaults write com.apple.Safari DebugSafari4TabBarIsOnTop -bool NO .] On updates and restarts. Speaking of Safari 4, why can't Apple come up with an update procedure that doesn't require restarting so often? When I first tried to install the new version of Safari, I was told I needed to install the latest Security Update first. Doing this required that I restart my Mac (which is precisely why I hadn't yet ...

Related: security update 2009-001 problems
Reports of startup issues after 2009-001 Security UpdateThe Unofficial Apple Weblog (TUAW)
Over the weekend, the mailbag caught a few notes of problems starting up once Leopard users had applied the 2009-001 Security Update (thanks @danielbru ), and on Friday the spotty issue was noted by MacFixIt as well . Affected users report a variety of symptoms: the dreaded 'boot disk not ...