<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:go='http://ns.gigaom.com/'
xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>GigaOM &#187; Apple</title>
	<atom:link href="http://gigaom.com/apple/tag/patch/feed/" rel="self" type="application/rss+xml" />
	<link>http://gigaom.com</link>
	<description></description>
	<lastBuildDate>Fri, 10 Feb 2012 12:29:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='gigaom.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/0db8f6557d022075dbbf010c54d46d93?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>GigaOM &#187; Apple</title>
		<link>http://gigaom.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://gigaom.com/osd.xml" title="GigaOM" />
	<atom:link rel='hub' href='http://gigaom.com/?pushpress=hub'/>
		<item>
		<title>OS X 10.6.3 Update Brings Record Number of Fixes</title>
		<link>http://gigaom.com/apple/os-x-10-6-3-update/</link>
		<comments>http://gigaom.com/apple/os-x-10-6-3-update/#comments</comments>
		<pubDate>Tue, 30 Mar 2010 18:57:58 +0000</pubDate>
		<dc:creator>Chris Brandrick</dc:creator>
				<category><![CDATA[Mac]]></category>
		<category><![CDATA[os x]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[Snow Leopard]]></category>
		<category><![CDATA[update]]></category>

		<guid isPermaLink="false">http://theappleblog.com/?p=43202</guid>
		<description><![CDATA[As predicted, an update to Apple's Snow Leopard and Leopard operating systems, which fixes a record number of vulnerabilities, is now available. The sizable patch, which weighs in at over 700MB, tends to a number of known security problems within the latest client and server versions of OS X, and is the largest update Apple has ever put out.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&amp;blog=14960843&amp;post=174100&amp;subd=gigaom2&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img  title="Snow Leopard" src="http://juicebox.theappleblog.com/e/ff8527ace79a7766.jpg/d" alt="Snow Leopard" width="195" height="200" class=" alignleft" />As <a href="http://gigaom.com/apple/10-6-3-is-imminent%E2%80%A6maybe-the-malwares-not-far-behind/">predicted</a>, an update to Apple&#8217;s Snow Leopard and Leopard operating systems, which fixes a record number of vulnerabilities, is now available.</p>
<p>The sizable patch, which weighs in at over 700MB, tends to a number of known security problems within the latest client and server versions of OS X, and is the largest update Apple has ever put out. This new update, known officially as &#8216;Security Update 2010-002&#8242;, fixes 92 problems in total, bringing Snow Leopard up to version number 10.6.3.</p>
<p>For those still running Leopard, and <a href="http://gigaom.com/apple/snow-leopards-been-out-for-six-months-why-are-so-many-of-us-still-using-leopard/">and plenty of you are</a>, this update offers 18 specific fixes for Apple&#8217;s older OS. Snow Leopard sees 29 distinct fixes, with the remaining 45 improvements being applicable to both operating systems.</p>
<p>Fixes found within the update include improving the reliability of Airport connections, minor adjustments to OS X&#8217;s Mail application, refinements to Time Machine&#8217;s backup process and more. One of the most noticeable inclusions within this update were the nine critical updates targeting QuickTime. However, the numerous updates to Apple&#8217;s media player, <a href="http://www.computerworld.com/s/article/9174337/Apple_delivers_record_monster_security_update">as pointed out by Computerworld</a>, come as little surprise due to the impending launch of the iPad. It&#8217;s increasingly common for Apple to update both QuickTime and its iTunes software ahead of the launch of a new device.</p>
<p>More information regarding the update, including a full run down of improvements, <a href="http://support.apple.com/kb/HT4014">can be found within Apple&#8217;s official support pages</a>. The update can be downloaded now either <a href="http://support.apple.com/kb/DL1018">online</a> or via OS X&#8217;s integrated system updater.</p>
<p>Let us know if you run into any issues with this upgrade.</p>
<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&amp;blog=14960843&amp;post=174100&amp;subd=gigaom2&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gigaom.com/apple/os-x-10-6-3-update/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
	 <go:thumbnail>http://gigapple.files.wordpress.com/2010/03/snowleopard_thumb.jpg?w=130</go:thumbnail> 
		<media:thumbnail url="http://gigapple.files.wordpress.com/2010/03/snowleopard_thumb.jpg?w=210" />
		<media:content url="http://gigapple.files.wordpress.com/2010/03/snowleopard_thumb.jpg?w=210" medium="image">
			<media:title type="html">snowleopard_thumb</media:title>
		</media:content>

		<media:content url="http://0.gravatar.com/avatar/2c0dbb32ee274187003b1ded2d11dea0?s=96&#38;d=retro&#38;r=PG" medium="image">
			<media:title type="html">Chris</media:title>
		</media:content>

		<media:content url="http://juicebox.theappleblog.com/e/ff8527ace79a7766.jpg/d" medium="image">
			<media:title type="html">Snow Leopard</media:title>
		</media:content>
	</item>
		<item>
		<title>Microsoft Posts Patches on the Heels of Apple&#8217;s Security &amp; Firmware Updates</title>
		<link>http://gigaom.com/apple/microsoft-posts-patches-on-the-heels-of-apples-security-firmware-updates/</link>
		<comments>http://gigaom.com/apple/microsoft-posts-patches-on-the-heels-of-apples-security-firmware-updates/#comments</comments>
		<pubDate>Thu, 16 Oct 2008 11:00:21 +0000</pubDate>
		<dc:creator>Bob Rudis</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[pda]]></category>
		<category><![CDATA[pocket pc]]></category>
		<category><![CDATA[10.4]]></category>
		<category><![CDATA[10.5]]></category>
		<category><![CDATA[firmware]]></category>
		<category><![CDATA[Leopard]]></category>
		<category><![CDATA[Macbook]]></category>
		<category><![CDATA[MacBook Pro]]></category>
		<category><![CDATA[Office]]></category>
		<category><![CDATA[office 2004]]></category>
		<category><![CDATA[office 2008]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Software Update]]></category>
		<category><![CDATA[Tiger]]></category>

		<guid isPermaLink="false">http://theappleblog.com/?p=6965</guid>
		<description><![CDATA[Microsoft released three updates yesterday which fix bugs and address security concerns in their Office family of products and utilities. The first is for the Open XML File Format Converter, which bumps the version to 1.0.1 and fixes a remote code execution (rated by Microsoft as [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&amp;blog=14960843&amp;post=171770&amp;subd=gigaom2&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p class="excerpt">Microsoft released three updates yesterday which fix bugs and address security concerns in their Office family of products and utilities.</p>
<p>The first is for the <a href="http://support.microsoft.com/kb/958304">Open XML File Format Converter</a>, which bumps the version to 1.0.1 and fixes a remote code execution (rated by Microsoft as &#8220;important&#8221;) associated with security bulleting <a href="http://www.microsoft.com/technet/security/bulletin/ms08-057.mspx">MS08-057</a>. The Open XML Converter allows you to convert Open XML files that were created in Office 2008 for Mac or Office 2007 for Windows so that you can open, edit, and save them in earlier versions of Office for Mac. The <a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=2A8D9A3B-B8A4-43B6-82A6-A2E7D16AE11D">download</a> is 44MB and should be installed by anyone running Office 2004 or Office v. X on OS X 10.4.9 or higher.</p>
<p>Next up is Office 2004 with a <a href="http://download.microsoft.com/download/3/7/1/37145534-d697-4dd0-8013-deff419d0477/Office2004-1152UpdateEN.dmg">13MB patch</a> to version <a href="http://support.microsoft.com/kb/958312">11.5.2</a> which addresses <a href="http://www.microsoft.com/technet/security/bulletin/ms08-057.mspx">vulnerabilities</a> which could allow attackers to run code on your system.</p>
<p>Similarly, Microsoft Office 2008 for Mac kicks it up to <a href="http://support.microsoft.com/kb/958267">version 12.1.3</a> which addresses <a href="http://www.microsoft.com/technet/security/bulletin/ms08-057.mspx">similar vulnerabilities</a> as the Office 2004 update in this <a href="http://download.microsoft.com/download/4/d/4/4d4368a3-10f9-4814-823b-4e5ad0c5ca7e/Office2008-1213UpdateEN.dmg">154MB download</a>.</p>
<p>You can avoid all this work by <a href="http://www.microsoft.com/mac/help.mspx?CTT=PageView&amp;clr=99-0-0&amp;ep=7&amp;target=ffe35357-8f25-4df8-a0a3-c258526c64ea1033">letting Microsoft do the work for you</a> with their auto-update.<br />
<span id="more-171770"></span></p>
<h3>In Good Company</h3>
<p>Apple also posted <a href="http://support.apple.com/kb/HT3216">Security Update 2008-007</a> on October 9th, which addressed <strong>nineteen</strong> (19) groups of vulnerabilities across a wide spectrum of OS X 10.4 and OS X 10.5 built-in software. Of particular interest are:</p>
<ul>
<li>fixes to QuickLook crashes for users of Microsoft Excel</li>
<li>a patch to a local privilege escalation issue with the network stack</li>
<li>a fairly gnarly problem with launchd (specific to OS X 10.5.5) that can result in improper sandoxing of some scheduled applications</li>
<li>correction to a buffer overflow situation with ColorSync that can be taken advantage of with maliciously crafted images (those evil images again)</li>
</ul>
<p>Apple also updated trusted root certificates (which are an important component of ensuring secure network communications).</p>
<p>You can <a href="http://support.apple.com/kb/HT3216">check out the other vulnerabilities</a> that were corrected and grab them via Software Update or <a href="http://www.apple.com/support/downloads/">Apple Downloads</a> (between 31MB &amp; 200MB depending on your system).</p>
<h3>Firmware Updates Join The Frey</h3>
<p>Apple also <a href="http://www.apple.com/support/downloads/macbookmacbookprosoftwareupdate12.html">posted</a> MacBook/MacBook Pro Software Update 1.2 which &#8212; true to form &#8212; nebulously &#8220;improves compatibility with external displays and includes a variety of software fixes&#8221; (would anyone let Microsoft get away with this?). The <a href="http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=21650&amp;cat=59&amp;platform=osx&amp;method=sa/MacBookMacBookProSU1.2.dmg">45MB update</a> is available now.</p>
<p>The updates caused no issues for me, but I&#8217;d be interested to hear if anyone else experienced any problems or post-install issues.</p>
<p><strong>Related research and analysis from GigaOM Pro:</strong><br />Subscriber content. <a href="http://pro.gigaom.com/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171770+microsoft-posts-patches-on-the-heels-of-apples-security-firmware-updates&utm_content=hrbrmstr">Sign up for a free trial</a>.</p><ul><li><a href="http://pro.gigaom.com/2011/02/content-farms-the-players-the-benefits-the-risks/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171770+microsoft-posts-patches-on-the-heels-of-apples-security-firmware-updates&utm_content=hrbrmstr">Content Farms: The Players, The Benefits, The&nbsp;Risks</a></li><li><a href="http://pro.gigaom.com/2011/03/why-ipad-2-will-lead-consumers-into-the-post-pc-era/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171770+microsoft-posts-patches-on-the-heels-of-apples-security-firmware-updates&utm_content=hrbrmstr">Why iPad 2 Will Lead Consumers Into the Post-PC&nbsp;Era</a></li><li><a href="http://pro.gigaom.com/2011/03/the-near-term-evolution-of-social-commerce/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171770+microsoft-posts-patches-on-the-heels-of-apples-security-firmware-updates&utm_content=hrbrmstr">The Near-Term Evolution of Social&nbsp;Commerce</a></li></ul><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&amp;blog=14960843&amp;post=171770&amp;subd=gigaom2&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gigaom.com/apple/microsoft-posts-patches-on-the-heels-of-apples-security-firmware-updates/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a08d08f6b541441fccf36bc6392a0784?s=96&#38;d=retro&#38;r=PG" medium="image">
			<media:title type="html">hrbrmstr</media:title>
		</media:content>
	</item>
		<item>
		<title>Software Updates and New Releases for Week Ending 2008-10-04</title>
		<link>http://gigaom.com/apple/software-updates-and-new-releases-for-week-ending-2008-10-03/</link>
		<comments>http://gigaom.com/apple/software-updates-and-new-releases-for-week-ending-2008-10-03/#comments</comments>
		<pubDate>Tue, 07 Oct 2008 23:00:51 +0000</pubDate>
		<dc:creator>Bob Rudis</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[Mobile Tech]]></category>
		<category><![CDATA[fix]]></category>
		<category><![CDATA[new release]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[Software Update]]></category>

		<guid isPermaLink="false">http://theappleblog.com/?p=5734</guid>
		<description><![CDATA[My Apple TV woes managed to eat away at some of the time I would have dedicated to scouring for updates and new toys, but I managed to find some interesting applications and utilities. I didn&#8217;t have time to put Stainless (a Google Chrome-like browser for [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&amp;blog=14960843&amp;post=171710&amp;subd=gigaom2&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>My <a href="http://gigaom.com/apple/apple-tv-authorization-server-problem-causes-mass-factory-restores/">Apple TV woes</a> managed to eat away at some of the time I would have dedicated to scouring for updates and new toys, but  I managed to find some interesting applications and utilities. I didn&#8217;t have time to put <a href="http://www.stainlessapp.com/">Stainless</a> (a Google Chrome-like browser for OS X based on WebKit) through enough paces to really post, but wanted to give it a mention since it has some very interesting features and may be a glimpse into the future of Safari. I also wanted to take the opportunity to <a href="http://gigaom.com/apple/techspansion-shutting-down-development-of-visualhubisquint/">once-again</a> thank Tyler Loch for his work on <a href="http://www.techspansion.com/visualhub/">VisualHub</a> (and other goodies) over the years. Your contributions to  the OS X community will be sorely missed!</p>
<ul>
<li style="padding-bottom:12px"><img src="http://gigapple.files.wordpress.com/2008/10/aim-small.png?w=75&#038;h=75" alt="" title="aim-small" width="75" height="75"  class=" alignleft" /><a href="http://beta.aol.com/projects.php?project=aimformac">AIM for Mac &#8211; Beta 1</a> &#8211; Much to the surprise of many, AOL decided to release a new beta of their instant messenger for OS X. The big question, as a result, is &#8220;Why?&#8221;. After testing it out, I can find no compelling reason to switch from iChat or Adium and no features that would make this a &#8220;must-have&#8221; application, but I welcome your thoughts in the comments. [10.4/10.5; Intel/PPC] <i>Free!</i></li>
<li style="padding-bottom:12px"><img src="http://gigapple.files.wordpress.com/2008/10/gimp-small.png?w=75&#038;h=75" alt="" title="gimp-small" width="75" height="75"  class=" alignleft" /><a href="http://gimp-app.sourceforge.net/">Gimp.app &#8211; 2.6.0</a> &#8211; Hot on the heels of the official <a href="http://www.gimp.org/">Gimp release</a> comes the OS X native (non-X11) release, complete with enhanced toolbars/docks, full panning beyond the image border, much-improved free-select tool and snazzy improvements to brushes. Much of the enhancements were under-the-covers and provided a foundation for future crunchy-goodness by integrating <a href="http://gegl.org/">GCEL</a> (Generic Graphics Library), a powerful graph-based image processing framework (think &#8220;undo&#8221;) and support for a wider range of color models and pixel storage formats when reading or saving images. The developers also improved plug-in support.<br/><br/>The interface is not exactly perfectly Mac-like and feels awkward and clunky at times, but it is definitely usable and has a good feature set. Would you use it over Photoshop or even some of the newer Flash-based online editors? Let me know your thoughts! [10.4/10.5; Intel/PPC] <i>Free!</i></li>
<li style="padding-bottom:12px"><img src="http://gigapple.files.wordpress.com/2008/10/receipt-wallet-small.png?w=75&#038;h=75" alt="" title="receipt-wallet-small" width="75" height="75"  class=" alignleft" /><a href="http://www.receiptwallet.com/">ReceiptWallet &#8211; 2.0.8</a> &#8211; This minor update will make folks in Switzerland happy (fixes an issue with that locale), but also fixes a couple of other annoyances (a &#8220;Cancel&#8221; button one that was – on occasion – catching me) and a few bugs. [10.4/10.5; Intel/PPC] US$39.95</li>
<li style="padding-bottom:12px"><img src="http://gigapple.files.wordpress.com/2008/10/itunes-small.png?w=75&#038;h=75" alt="" title="itunes-small" width="75" height="75"  class=" alignleft" /><a href="http://www.apple.com/itunes/">Apple iTunes &#8211; 8.0.1</a> &#038; <a href="http://www.apple.com/appletv/">Apple TV &#8211; 2.2</a> &#8211; As you <a href="http://gigaom.com/apple/apple-tv-22-wish-lists-fail/">saw</a> on <a href="http://gigaom.com/apple/apple-tv-authorization-server-problem-causes-mass-factory-restores/">TAB</a>, iTunes and Apple TV received updates this past week. The former improves music playback during Genius playlist creation (along with other improvements), and the latter provides support for HD TV shows and tosses a Genius into the tiny box for good measure. [10.3.9 (Apple TV update)/10.4/10.5; Intel/PPC] <i>Free!</i></li>
<li style="padding-bottom:12px"><img src="http://gigapple.files.wordpress.com/2008/10/editra-small.png?w=75&#038;h=75" alt="" title="editra-small" width="75" height="75"  class=" alignleft" /><a href="http://editra.org/">Editra &#8211; 0.3.80</a> &#8211; Entering a candidate into the text editor fray on OS X takes guts. You are competing with the likes of BBEdit, TextMate, TextWrangler and many others, each of them having a loyal and vocal user-base. Editra is aimed squarely at the developers out there as it has most of the goodies you&#8217;ve come to expect (line numbering, commenting, indenting, syntax highlighting, etc.). The interface is straightforward enough, but it is obvious that the &#8220;0.x&#8221; version numbering is accurate since there is much room for many refinements. It already supports plug-ins (written in Python) and has the benefit of being cross-platform (it is written with the wxWidgets library), so you can use slide between platforms without losing your editing mojo. This application is definitely something to keep on your radar and in your RSS feeds. [10.4/10.5; Intel/PPC] <i>Free!</i></li>
<li style="padding-bottom:12px"><img src="http://gigapple.files.wordpress.com/2008/10/perian-small.png?w=75&#038;h=75" alt="" title="perian-small" width="75" height="75"  class=" alignleft" /><a href="http://perian.org/">Perian &#8211; 1.1.1</a> &#8211; The self-dubbed &#8220;Swiss-Army knife for QuickTime&#8221; releases a two-dot update that I would have missed since the &#8220;update&#8221; button in the PrefPane did not work (and I just happened to hit their site from the other button in the PrefPane). This minor update fixes a problem with H.264 in AVI files, corrects a frame skipping issue, adds some codecs and incorporates a few additional bug fixes and feature tweaks. [10.4/10.5; Intel/PPC] <i>Free!</i></li>
<li><img src="http://gigapple.files.wordpress.com/2008/10/schnippel-small.png?w=75&#038;h=75" alt="" title="schnippel-small" width="75" height="75"  class=" alignleft" /><a href="http://myownapp.com/site/moapp2.0/freestuff/freestuff.php5">Schnippselchen Pro &#8211; 2.0.1</a> &#8211; I&#8217;ve been <i>slowly</i> getting back into software development (that may or may not be obvious from my posts) and came across this code-snippet saver which allows you to store, track and fully manage your bits of useful source with full support for syntax highlighting and drag-and-drop to Xcode or TextMate. The Mail-like interface should be quite accessible to everyone and the builtin search makes it pretty simple to find what you are looking for (especially if you&#8217;ve commented the snippets well). You can add a custom icon to each snippet and backup, export or share your library. The manual states that the app &#8220;will only store the data as long as [it] is running&#8221; but all my test snippets have been available across multiple launches. [10.5; Intel/PPC] <i>Free?</i></li>
</ul>
<p>Remember, drop me a note on Twitter (<a href="http://twitter.com/hrbrmstr">@hrbrmstr</a>) or in the comments if there is something you&#8217;d like me to try!</p>
<p><strong>Related research and analysis from GigaOM Pro:</strong><br />Subscriber content. <a href="http://pro.gigaom.com/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171710+software-updates-and-new-releases-for-week-ending-2008-10-03&utm_content=hrbrmstr">Sign up for a free trial</a>.</p><ul><li><a href="http://pro.gigaom.com/2011/02/content-farms-the-players-the-benefits-the-risks/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171710+software-updates-and-new-releases-for-week-ending-2008-10-03&utm_content=hrbrmstr">Content Farms: The Players, The Benefits, The&nbsp;Risks</a></li><li><a href="http://pro.gigaom.com/2011/03/why-ipad-2-will-lead-consumers-into-the-post-pc-era/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171710+software-updates-and-new-releases-for-week-ending-2008-10-03&utm_content=hrbrmstr">Why iPad 2 Will Lead Consumers Into the Post-PC&nbsp;Era</a></li><li><a href="http://pro.gigaom.com/2011/03/the-near-term-evolution-of-social-commerce/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171710+software-updates-and-new-releases-for-week-ending-2008-10-03&utm_content=hrbrmstr">The Near-Term Evolution of Social&nbsp;Commerce</a></li></ul><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&amp;blog=14960843&amp;post=171710&amp;subd=gigaom2&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gigaom.com/apple/software-updates-and-new-releases-for-week-ending-2008-10-03/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a08d08f6b541441fccf36bc6392a0784?s=96&#38;d=retro&#38;r=PG" medium="image">
			<media:title type="html">hrbrmstr</media:title>
		</media:content>

		<media:content url="http://gigapple.files.wordpress.com/2008/10/aim-small.png" medium="image">
			<media:title type="html">aim-small</media:title>
		</media:content>

		<media:content url="http://gigapple.files.wordpress.com/2008/10/gimp-small.png" medium="image">
			<media:title type="html">gimp-small</media:title>
		</media:content>

		<media:content url="http://gigapple.files.wordpress.com/2008/10/receipt-wallet-small.png" medium="image">
			<media:title type="html">receipt-wallet-small</media:title>
		</media:content>

		<media:content url="http://gigapple.files.wordpress.com/2008/10/itunes-small.png" medium="image">
			<media:title type="html">itunes-small</media:title>
		</media:content>

		<media:content url="http://gigapple.files.wordpress.com/2008/10/editra-small.png" medium="image">
			<media:title type="html">editra-small</media:title>
		</media:content>

		<media:content url="http://gigapple.files.wordpress.com/2008/10/perian-small.png" medium="image">
			<media:title type="html">perian-small</media:title>
		</media:content>

		<media:content url="http://gigapple.files.wordpress.com/2008/10/schnippel-small.png" medium="image">
			<media:title type="html">schnippel-small</media:title>
		</media:content>
	</item>
		<item>
		<title>Firefox 3.0.2 Fixes Security Issues &amp; OS X Bugs</title>
		<link>http://gigaom.com/apple/firefox-302-fixes-security-issues-os-x-bugs/</link>
		<comments>http://gigaom.com/apple/firefox-302-fixes-security-issues-os-x-bugs/#comments</comments>
		<pubDate>Wed, 24 Sep 2008 18:00:22 +0000</pubDate>
		<dc:creator>Bob Rudis</dc:creator>
				<category><![CDATA[CES 2007]]></category>
		<category><![CDATA[Commentary]]></category>
		<category><![CDATA[bug]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[update]]></category>

		<guid isPermaLink="false">http://theappleblog.com/?p=5041</guid>
		<description><![CDATA[The Mozilla crew have updated Firefox 3 and Firefox 2 to address security vulnerabilities and (in the case of version 3) bugs &#038; usability issues, including fixes for Mac-specific bugs. Firefox 3 had five security issues including two critical ones that could lead to either memory [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&amp;blog=14960843&amp;post=171669&amp;subd=gigaom2&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img src="http://gigapple.files.wordpress.com/2008/09/key.png?w=150&#038;h=151" alt="" title="key" width="150" height="151"  class=" alignleft" />
<p class="excerpt">The Mozilla crew have updated <a href="http://getfirefox.com/">Firefox 3</a> and <a href="http://www.mozilla.com/firefox/all-older.html">Firefox 2</a> to address security vulnerabilities and (in the case of version 3) bugs &#038; usability issues, including fixes for Mac-specific bugs.</p>
<p>Firefox 3 had <a href="http://www.mozilla.org/security/known-vulnerabilities/firefox30.html#firefox3.0.2">five security issues</a> including two <b>critical</b> ones that could lead to either memory corruption or privilege escalation. Firefox 2 fixed nine security vulnerabilities, four of which were <b>critical</b>.</p>
<p>OS X users will see fewer problems with keyboard shortcuts, be able to enter Japanese, Korean, Chinese and Indic characters into Flash object text fields and store user profiles on AFP shares.</p>
<p>As I continue to use two browsers regularly (Firefox and Safari), Firefox continues to re-grow on me, especially with its rich extension support. If you do use non-Apple-provided browsers, it is vital that you stay on top of updates as you never know when you will find yourself surfing to a site with malicious content. Firefox makes it almost as simple as Apple&#8217;s Software Update by letting you choose between <b>Help &rarr; Check for Updates&#8230;</b> or setting up automatic update checking under <b>Firefox &rarr; Preferences&#8230; &rarr; Advanced &rarr; Update</b>.</p>
<p><img src="http://gigapple.files.wordpress.com/2008/09/advanced.png?w=604" alt="" title="advanced"  class=" alignleft" /></p>
<p>If you&#8217;ve already upgraded, let other TAB readers know how you fared by dropping a note in the comments!</p>
<p><strong>Related research and analysis from GigaOM Pro:</strong><br />Subscriber content. <a href="http://pro.gigaom.com/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171669+firefox-302-fixes-security-issues-os-x-bugs&utm_content=hrbrmstr">Sign up for a free trial</a>.</p><ul><li><a href="http://pro.gigaom.com/2011/02/content-farms-the-players-the-benefits-the-risks/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171669+firefox-302-fixes-security-issues-os-x-bugs&utm_content=hrbrmstr">Content Farms: The Players, The Benefits, The&nbsp;Risks</a></li><li><a href="http://pro.gigaom.com/2009/07/virtual-worlds-trends-and-opportunities/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171669+firefox-302-fixes-security-issues-os-x-bugs&utm_content=hrbrmstr">Virtual Worlds: Trends and&nbsp;Opportunities</a></li><li><a href="http://pro.gigaom.com/2011/03/why-ipad-2-will-lead-consumers-into-the-post-pc-era/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171669+firefox-302-fixes-security-issues-os-x-bugs&utm_content=hrbrmstr">Why iPad 2 Will Lead Consumers Into the Post-PC&nbsp;Era</a></li></ul><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&amp;blog=14960843&amp;post=171669&amp;subd=gigaom2&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gigaom.com/apple/firefox-302-fixes-security-issues-os-x-bugs/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a08d08f6b541441fccf36bc6392a0784?s=96&#38;d=retro&#38;r=PG" medium="image">
			<media:title type="html">hrbrmstr</media:title>
		</media:content>

		<media:content url="http://gigapple.files.wordpress.com/2008/09/key.png" medium="image">
			<media:title type="html">key</media:title>
		</media:content>

		<media:content url="http://gigapple.files.wordpress.com/2008/09/advanced.png" medium="image">
			<media:title type="html">advanced</media:title>
		</media:content>
	</item>
		<item>
		<title>Microsoft Updates Office 2008 For Mac To 12.1.2, Office 2004 for Mac to 11.5.1</title>
		<link>http://gigaom.com/apple/microsoft-updates-office-2008-for-mac-to-1212-office-2004-for-mac-to-1151/</link>
		<comments>http://gigaom.com/apple/microsoft-updates-office-2008-for-mac-to-1212-office-2004-for-mac-to-1151/#comments</comments>
		<pubDate>Tue, 12 Aug 2008 23:30:17 +0000</pubDate>
		<dc:creator>Bob Rudis</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[entourage]]></category>
		<category><![CDATA[Excel]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Office]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[PowerPoint]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Software Update]]></category>
		<category><![CDATA[Word]]></category>

		<guid isPermaLink="false">http://theappleblog.com/?p=4131</guid>
		<description><![CDATA[The fine folks in Redmond have released Microsoft Office 2008 for Mac 12.1.2 update which includes stability and performance enhancements for Office 2008, Office 2008 Home and Student Edition, Office 2008 Special Media Edition, Word 2008, Excel 2008, PowerPoint 2008, and Entourage 2008. In addition, this [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&amp;blog=14960843&amp;post=171594&amp;subd=gigaom2&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The fine folks in Redmond have released <a href="http://www.microsoft.com/mac/downloads.mspx?pid=Mactopia_Office2008&#038;fid=9515C70D-BE80-4ADE-856A-EA542F7D84E1#viewer">Microsoft Office 2008 for Mac 12.1.2</a> update which includes <a href="http://go.microsoft.com/fwlink/?LinkId=122674">stability and performance enhancements</a> for Office 2008, Office 2008 Home and Student Edition, Office 2008 Special Media Edition, Word 2008, Excel 2008, PowerPoint 2008, and Entourage 2008. In addition, this fixes <a href="http://www.microsoft.com/protect/computer/updates/bulletins/200808.mspx">several vulnerabilities</a>, some of which may allow an attacker to run code on your machine if you open malicious document. The download is 160MB and is available at the aforementioned URL (English direct download <a href="http://download.microsoft.com/download/2/a/5/2a55799e-0668-4468-a0a3-8b0e78cf7865/Office2008-1212UpdateEN.dmg">here</a>) or via the Microsoft AutoUpdate agent.</p>
<p>Microsoft has stated that you should have installed the <a href="http://go.microsoft.com/fwlink/?LinkId=122677">12.1.1 Update</a> prior to installing 12.1.2.</p>
<p>In similar fashion, Office 2004 has been updated to <a href="http://www.microsoft.com/mac/downloads.mspx?pid=Mactopia_Office2004&#038;fid=EBD3AF0C-3F62-4D18-BF45-881655683BD5#viewer">11.5.1</a> which also has security, <a href="http://go.microsoft.com/fwlink/?LinkId=122666">stability and performance</a> fixes for Office 2004 Standard Edition, Office 2004 Student and Teacher Edition, Office 2004 Professional Edition, Word 2004, Excel 2004, PowerPoint 2004 and Entourage 2004. The 15MB download (<a href="http://download.microsoft.com/download/7/4/b/74b0b314-a94a-479c-ad15-b73c5c6d1810/Office2004-1151UpdateEN.dmg">English direct</a>) is available via similar channels as the Office 2008 update.</p>
<p>Microsoft has stated that you should have installed the <a href="http://go.microsoft.com/fwlink/?LinkId=1226697">11.5.0 Update</a> prior to installing 11.5.1.</p>
<p>For what it&#8217;s worth: no problems on my end for Office 12.1.2, but I have not had an opportunity to do extensive testing. Since these updates do include security fixes (have I mentioned just how annoying it is when vendors mix security patches with other fixes?) you should install this immediately (<i>after testing</i>, if you&#8217;re in a more formal/larger production/working environment).</p>
<p>AutoUpdate should engage at some point today (it has not been populated as of this writing) and the direct links to the info-pages have not percolated to all of Microsoft&#8217;s web farm yet.</p>
<p>Let TAB readers know your post-update praises or woes in the comments!</p>
<p><strong>Related research and analysis from GigaOM Pro:</strong><br />Subscriber content. <a href="http://pro.gigaom.com/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171594+microsoft-updates-office-2008-for-mac-to-1212-office-2004-for-mac-to-1151&utm_content=hrbrmstr">Sign up for a free trial</a>.</p><ul><li><a href="http://pro.gigaom.com/2011/02/content-farms-the-players-the-benefits-the-risks/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171594+microsoft-updates-office-2008-for-mac-to-1212-office-2004-for-mac-to-1151&utm_content=hrbrmstr">Content Farms: The Players, The Benefits, The&nbsp;Risks</a></li><li><a href="http://pro.gigaom.com/2011/02/what-googles-honeycomb-means-for-apple-and-microsoft/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171594+microsoft-updates-office-2008-for-mac-to-1212-office-2004-for-mac-to-1151&utm_content=hrbrmstr">What Google&#8217;s Honeycomb Means for Apple and&nbsp;Microsoft</a></li><li><a href="http://pro.gigaom.com/2011/02/the-future-of-work-platforms-an-overview/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171594+microsoft-updates-office-2008-for-mac-to-1212-office-2004-for-mac-to-1151&utm_content=hrbrmstr">The Future of Work Platforms: An&nbsp;Overview</a></li></ul><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&amp;blog=14960843&amp;post=171594&amp;subd=gigaom2&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gigaom.com/apple/microsoft-updates-office-2008-for-mac-to-1212-office-2004-for-mac-to-1151/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a08d08f6b541441fccf36bc6392a0784?s=96&#38;d=retro&#38;r=PG" medium="image">
			<media:title type="html">hrbrmstr</media:title>
		</media:content>
	</item>
		<item>
		<title>Security Update 2008-05 : DNS Flaw Finally Fixed</title>
		<link>http://gigaom.com/apple/security-update-2008-05-dns-flaw-finally-fixed/</link>
		<comments>http://gigaom.com/apple/security-update-2008-05-dns-flaw-finally-fixed/#comments</comments>
		<pubDate>Fri, 01 Aug 2008 17:04:45 +0000</pubDate>
		<dc:creator>Bob Rudis</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Style and Etiquette]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[Copyright]]></category>
		<category><![CDATA[dns cache poisoning]]></category>
		<category><![CDATA[infringement]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[photo]]></category>
		<category><![CDATA[photograph]]></category>
		<category><![CDATA[rights]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Software Update]]></category>

		<guid isPermaLink="false">http://theappleblog.com/?p=3949</guid>
		<description><![CDATA[Apple released Security Update 2008-05 which contains fixes for: an Open Scripting Architecture (CVE-2008-2830) privilege elevation issue [10.4/10.5 Workstation &#038; Server] a filename handling issue in CarbonCore (CVE-2008-2320) which may lead to an application Denial of Service (DoS) or arbitrary code execution [10.4/10.5 Workstation &#038; Server] [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&amp;blog=14960843&amp;post=171579&amp;subd=gigaom2&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Apple released <a href="http://support.apple.com/kb/HT2647">Security Update 2008-05</a> which contains fixes for:</p>
<ul>
<li>an Open Scripting Architecture (<a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2830">CVE-2008-2830</a>) privilege elevation issue [10.4/10.5 Workstation &#038; Server]</li>
<li>a filename handling issue in CarbonCore (<a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2320">CVE-2008-2320</a>) which may lead to an application Denial of Service (DoS) or arbitrary code execution [10.4/10.5 Workstation &#038; Server]</li>
<li>a web-exploitable CoreGraphics issue (<a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2321">CVE-2008-2321</a>) that could lead to application DoS or arbitrary code execution [10.4/10.5 Workstation &#038; Server]</li>
<li>another CoreGraphics issue (<a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2322">CVE-2008-2322</a>) with PDF rendering, leading to application DoS or arbitrary code execution [10.4/10/5 Workstation &#038; Server]</li>
<li>an issue with DataDetectors (<a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2323">CVE-2008-2323</a>) where maliciously crafted content could lead to an application DoS [10.5 Workstation &#038; Server]</li>
<li>a really cool permissions issue with Disk Utility (<a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2324">CVE-2008-2324</a>) that would have allowed local users to act with system privileges [10.4 Workstation &#038; Server]</li>
<li>an issue with OpenLDAP (<a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2952">CVE-2008-2952</a>) where an attacker could have created an application DoS [10.4/10.5 Workstation &#038; Server]</li>
<li>another DoS potential in OpenSSL (<a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5135">CVE-2007-5135</a>) if maliciously crafted bad packets are processed [10.4/10.5 Workstation &#038; Server]</li>
<li>five PHP 5 fixes [10.5 Workstation &#038; Server]</li>
<li>a QuickLook issue with Microsoft Office documents (<a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2325">CVE-2008-2325</a>) causing either an application DoS or arbitrary code execution [10.5 Workstation &#038; Server]</li>
<li>two rsync vulnerabilities that may result in data access outside the module root [10.4/105 Workstation &#038; Server]</li>
</ul>
<p>The &#8220;big daddy&#8221; of this update is a fix for the <a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1447">DNS cache poisoning problem</a> that has been in the <a href="http://db.tidbits.com/article/9706">Apple</a> and general tech &#038; security news recently. This is a pretty severe issue as DNS is the backbone of how systems &#038; application get  IP addresses from host names (so they know where to send you on the Intenet), and the ability to corrupt those databases means you really cannot trust where your network packets are going. Apple is the <b>last</b> major vendor to release a fix for this flaw and rightfully deserves some flack for it since they could have deployed the patch on July 8th with the majority of the other vendors, but chose to wait until this update bundle was ready to release.</p>
<p>OS X Server is the most likely candidate for actually running <a href="http://www.isc.org/index.pl?/sw/bind/">BIND</a> (the process that manages DNS on a system) and you need to patch <b>IMMEDIATELY</b> if you are using it. It takes a bit of work to do this on plain-old Mac OS X, but you should run the update as soon as possible as well (especially for some of the other fixes).</p>
<p>A gaping hole still exists in OS X 10.3 and below you will need to do a bit of work (download, compile &#038; install the package from <a href="http://www.isc.org/index.pl?/sw/bind/">the ISC</a> by hand) if you are still running those systems and hosting DNS . While supporting older operating system releases presents a real challenge to companies like Apple &#038; Microsoft, it is not unreasonable to expect there to be a decent number of 10.3 systems in the wild that need tending to and Apple should have done more to ensure coverage for those installations (or at least have provided a series of steps one could take to fix the issue).</p>
<p>Apple clearly dropped the ball here and has called into question their true commitment to security on their OS X platform or at least their ability to react quickly given all of the efforts they have in play. One also needs to remember that a version of OS X runs on the iPhone, iPhone 3G and iPod Touch and it is unclear whether the issues with CoreGraphics and DataDetectors exist on those platforms as well. It is much more difficult to both issue firmware updates and ensure decent update coverage with those mobile devices and Apple may need to come up with a way to deploy critical security fixes over-the-air directly to them rather than force consumers to do a full sync/update to remain secure.</p>
<p>The security update should show up in Software Update and is also available via <a href="http://support.apple.com/kb/HT2647">direct download</a> from Apple.</p>
<p>Let TAB readers know your take on how Apple handled this situation by dropping a note in the comments!</p>
<p><strong>Related research and analysis from GigaOM Pro:</strong><br />Subscriber content. <a href="http://pro.gigaom.com/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171579+security-update-2008-05-dns-flaw-finally-fixed&utm_content=hrbrmstr">Sign up for a free trial</a>.</p><ul><li><a href="http://pro.gigaom.com/2011/02/content-farms-the-players-the-benefits-the-risks/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171579+security-update-2008-05-dns-flaw-finally-fixed&utm_content=hrbrmstr">Content Farms: The Players, The Benefits, The&nbsp;Risks</a></li><li><a href="?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171579+security-update-2008-05-dns-flaw-finally-fixed&utm_content=hrbrmstr"></a></li><li><a href="http://pro.gigaom.com/2011/03/why-ipad-2-will-lead-consumers-into-the-post-pc-era/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171579+security-update-2008-05-dns-flaw-finally-fixed&utm_content=hrbrmstr">Why iPad 2 Will Lead Consumers Into the Post-PC&nbsp;Era</a></li></ul><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&amp;blog=14960843&amp;post=171579&amp;subd=gigaom2&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gigaom.com/apple/security-update-2008-05-dns-flaw-finally-fixed/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a08d08f6b541441fccf36bc6392a0784?s=96&#38;d=retro&#38;r=PG" medium="image">
			<media:title type="html">hrbrmstr</media:title>
		</media:content>
	</item>
		<item>
		<title>OS X 10.5.4 Released To The Wild + Other Apple Updates</title>
		<link>http://gigaom.com/apple/os-x-1054-released-to-the-wild-other-apple-updates/</link>
		<comments>http://gigaom.com/apple/os-x-1054-released-to-the-wild-other-apple-updates/#comments</comments>
		<pubDate>Tue, 01 Jul 2008 18:29:36 +0000</pubDate>
		<dc:creator>Bob Rudis</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[bug fix]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Software Update]]></category>

		<guid isPermaLink="false">http://theappleblog.com/?p=3615</guid>
		<description><![CDATA[Apple has released OS X 10.5.4 (59 MB via Software Update) to the masses which includes the content of Security Update 2008-04. The update also includes improvements to AirPort reliability and speed, many iCal improvements, two secure surfing improvements to Safari and three Spaces &#038; Exposé [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&amp;blog=14960843&amp;post=171522&amp;subd=gigaom2&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img src="http://gigapple.files.wordpress.com/2008/07/software-upate.png?w=128&#038;h=128" alt="" title="software-upate" width="128" height="128"  class=" alignleft" />Apple has <a href="http://support.apple.com/kb/HT1994">released OS X 10.5.4</a>  (59 MB via Software Update) to the masses which includes the content of <a href="http://support.apple.com/kb/HT2163">Security Update 2008-04</a>. The update also includes improvements to AirPort reliability and speed, many iCal improvements, two secure surfing improvements to Safari and three Spaces &#038; Exposé bugs.</p>
<p>The Security Update fixes 21 security issues in OS X 10.4 and 14 security issues in OS X 10.5. Fixes for especially nasty bugs include:</p>
<ul>
<li>CVE-2008-2309 which adds .xht and .xhtm files to the system&#8217;s list of content types that will be flagged as potentially unsafe under certain circumstances, such as when they are downloaded from a web page. While these content types are not automatically launched, if manually opened they could lead to the execution of a malicious payload. This update improves the system&#8217;s ability to notify users before handling .xht and .xhtm files.<br/></li>
<li>CVE-2008-2314 which disables hot corners when the screen lock is active (When the system is set to require a password to wake from sleep or screen saver, and Exposé hot corners are set, a person with physical access may have been able to access the system without entering a password prior to this fix.)<br/></li>
<li>CVE-2008-0960 which performs better validation of SNMPv3 packets (SNMP can be used to retrieve information about your system).</li>
</ul>
<p>OS X 10.5.4 can be installed via Software Update or <a href="http://www.apple.com/support/downloads/">downloaded directly from Apple</a>.</p>
<p>Users still running OS X 10.4.11 can also (along with the Security Update) look forward to a <a href="http://support.apple.com/kb/HT2165">Safari 3.1.2 update</a> as well, which includes a fix to a security issue (CVE-2008-2307) involving a memory corruption issue that exists in WebKit&#8217;s handling of JavaScript arrays. Without the patch, users who visit a maliciously crafted website may see unexpected application terminations or be vulnerable to arbitrary code execution. Apple engineers improved bounds checking to fix the problem.</p>
<p>If you have installed any of these updates, drop a note in the comments if you experienced any issues or if you can confirm whether a particular issue you have been seeing has been fixed.</p>
<p><strong>Related research and analysis from GigaOM Pro:</strong><br />Subscriber content. <a href="http://pro.gigaom.com/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171522+os-x-1054-released-to-the-wild-other-apple-updates&utm_content=hrbrmstr">Sign up for a free trial</a>.</p><ul><li><a href="http://pro.gigaom.com/2011/03/why-ipad-2-will-lead-consumers-into-the-post-pc-era/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171522+os-x-1054-released-to-the-wild-other-apple-updates&utm_content=hrbrmstr">Why iPad 2 Will Lead Consumers Into the Post-PC&nbsp;Era</a></li><li><a href="http://pro.gigaom.com/2011/03/the-near-term-evolution-of-social-commerce/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171522+os-x-1054-released-to-the-wild-other-apple-updates&utm_content=hrbrmstr">The Near-Term Evolution of Social&nbsp;Commerce</a></li><li><a href="http://pro.gigaom.com/2011/02/content-farms-the-players-the-benefits-the-risks/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171522+os-x-1054-released-to-the-wild-other-apple-updates&utm_content=hrbrmstr">Content Farms: The Players, The Benefits, The&nbsp;Risks</a></li></ul><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&amp;blog=14960843&amp;post=171522&amp;subd=gigaom2&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gigaom.com/apple/os-x-1054-released-to-the-wild-other-apple-updates/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a08d08f6b541441fccf36bc6392a0784?s=96&#38;d=retro&#38;r=PG" medium="image">
			<media:title type="html">hrbrmstr</media:title>
		</media:content>

		<media:content url="http://gigapple.files.wordpress.com/2008/07/software-upate.png" medium="image">
			<media:title type="html">software-upate</media:title>
		</media:content>
	</item>
		<item>
		<title>Unpatched Flaw In Apple Remote Desktop Brings About Trojans &amp; Community Fixes</title>
		<link>http://gigaom.com/apple/unpatched-flaw-in-apple-remote-desktop-brings-about-trojans-community-fixes/</link>
		<comments>http://gigaom.com/apple/unpatched-flaw-in-apple-remote-desktop-brings-about-trojans-community-fixes/#comments</comments>
		<pubDate>Tue, 24 Jun 2008 21:36:23 +0000</pubDate>
		<dc:creator>Bob Rudis</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[Commentary]]></category>
		<category><![CDATA[apple remote desktop]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[trojan horse]]></category>
		<category><![CDATA[workaround]]></category>

		<guid isPermaLink="false">http://theappleblog.com/?p=3553</guid>
		<description><![CDATA[Much ado has been made this week regarding the recent Apple Remote Desktop Root Privilege Escalation Vulnerability. The short story is that there is a flaw in a piece of software that Apple ships &#038; installs with every Leopard instance which enables a local user to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&amp;blog=14960843&amp;post=171503&amp;subd=gigaom2&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img src="http://gigapple.files.wordpress.com/2008/06/lock-icon.gif?w=125&#038;h=181" alt="" title="lock-icon" width="125" height="181"  class=" alignleft" />Much ado has been made this week regarding the <a href="http://isc.sans.org/diary.html?storyid=4604&#038;rss">recent Apple Remote Desktop Root Privilege Escalation Vulnerability</a>. The short story is that there is a flaw in a piece of software that Apple ships &#038; installs with every Leopard instance which enables a local user to run scripts with <code>root</code> privileges (meaning they can do <i>anything</i> on the system).</p>
<p>As you may have <a href="http://www.intego.com/news/ism0802.asp">read</a>, this flaw is not capable of being exploited remotely, but multiple variants of a <a href="http://www.theregister.co.uk/2008/06/23/mac_trojan/">new Trojan</a> (dubbed &#8220;AppleScript-THT&#8221;) are floating around the internets which wreak all sorts of havoc on your system once infected. Some install keystroke logging, usurp your iSight camera to take pictures or even capturing screenshots (some do much worse).</p>
<p>The Washington Post has a great <a href="http://blog.washingtonpost.com/securityfix/2008/06/serious_security_vulnerabilty_1.html">blog post</a> which gives a great amount of detail on the problem and even mentions a few solutions. The quickest way (until Apple releases a patch) to protect yourself is to open up a Terminal window and enter the following text:</p>
<div style="width:500px;white-space:nowrap;overflow:scroll=yes;overflow-x:scroll; overflow-y:hidden;"><code>osascript -e 'tell app "ARDAgent" to do shell script "chmod 0555 /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/MacOS/ARDAgent"';</code></div>
<p>If that was successful, then you should <b>not</b> see &#8220;root&#8221; when you paste this into the Terminal window:</p>
<p><code>osascript -e 'tell app "ARDAgent" to do shell script "whoami"';</code></p>
<p><a href="http://www.securemac.com/applescript-tht-trojan-horse.php">SecureMac</a> has updated MacScan to account for these new beasts and DAT updates from other vendors are forthcoming.</p>
<p><b>Until Apple releases a patch and you install it</b> be very careful what you download and execute, both from your browser or chat clients.</p>
<p>If you have any questions or concerns, please drop a note in the comments and I will monitor this thread closely over the coming days to try to help as much as possible. Watch for a TAB post when Apple issues a fix.</p>
<p><strong>Related research and analysis from GigaOM Pro:</strong><br />Subscriber content. <a href="http://pro.gigaom.com/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171503+unpatched-flaw-in-apple-remote-desktop-brings-about-trojans-community-fixes&utm_content=hrbrmstr">Sign up for a free trial</a>.</p><ul><li><a href="http://pro.gigaom.com/2011/02/content-farms-the-players-the-benefits-the-risks/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171503+unpatched-flaw-in-apple-remote-desktop-brings-about-trojans-community-fixes&utm_content=hrbrmstr">Content Farms: The Players, The Benefits, The&nbsp;Risks</a></li><li><a href="http://pro.gigaom.com/2011/03/why-ipad-2-will-lead-consumers-into-the-post-pc-era/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171503+unpatched-flaw-in-apple-remote-desktop-brings-about-trojans-community-fixes&utm_content=hrbrmstr">Why iPad 2 Will Lead Consumers Into the Post-PC&nbsp;Era</a></li><li><a href="http://pro.gigaom.com/2011/03/the-near-term-evolution-of-social-commerce/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171503+unpatched-flaw-in-apple-remote-desktop-brings-about-trojans-community-fixes&utm_content=hrbrmstr">The Near-Term Evolution of Social&nbsp;Commerce</a></li></ul><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&amp;blog=14960843&amp;post=171503&amp;subd=gigaom2&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gigaom.com/apple/unpatched-flaw-in-apple-remote-desktop-brings-about-trojans-community-fixes/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a08d08f6b541441fccf36bc6392a0784?s=96&#38;d=retro&#38;r=PG" medium="image">
			<media:title type="html">hrbrmstr</media:title>
		</media:content>

		<media:content url="http://gigapple.files.wordpress.com/2008/06/lock-icon.gif" medium="image">
			<media:title type="html">lock-icon</media:title>
		</media:content>
	</item>
		<item>
		<title>Microsoft Patches Office, Commits to VBA Support</title>
		<link>http://gigaom.com/apple/microsoft-patches-office-commits-to-vba-support/</link>
		<comments>http://gigaom.com/apple/microsoft-patches-office-commits-to-vba-support/#comments</comments>
		<pubDate>Tue, 13 May 2008 18:29:49 +0000</pubDate>
		<dc:creator>Bob Rudis</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[Commentary]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[microsoft office]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[service pack]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://theappleblog.com/?p=3252</guid>
		<description><![CDATA[Microsoft has been busy today, releasing security updates, announcing a new service pack and committing to restoring functionality to their Mac office suite. Yep, It&#8217;s Patch Tuesday Again Microsoft released security bulletin MS08-014 today that contains a patch to a remote code execution vulnerability effecting Microsoft [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&amp;blog=14960843&amp;post=171405&amp;subd=gigaom2&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img src="http://gigapple.files.wordpress.com/2008/05/office2008macbox.png?w=112&#038;h=141" alt="" width="112" height="141"  class=" alignleft" />
<p class="excerpt">Microsoft has been busy today, releasing security updates, announcing a new service pack and committing to restoring functionality to their Mac office suite.</p>
<h3>Yep, It&#8217;s Patch Tuesday Again</h3>
<p>Microsoft <a href="http://www.microsoft.com/technet/security/bulletin/ms08-014.mspx">released security bulletin MS08-014</a> today that contains a patch to a remote code execution vulnerability effecting Microsoft Office 2004 &amp; 2008 for Macintosh. Office 2004 is bumped up to <a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=95DCEB37-B35F-46DB-B280-DB0F3B298AA9&amp;displaylang=en">version 11.4.1</a> and primarily contains <a href="http://support.microsoft.com/default.aspx/kb/949357">security &amp; stability fixes</a>. Office 2008 bumps up to <a>version 12.1.0</a> and includes security fixes along with a <a href="http://support.microsoft.com/kb/948057">plethora of other improvements</a>. Both updates are available via Office software update or via direct download from the aforementioned links.</p>
<h3>Get Your Red Hot Office 2008 SP1!</h3>
<p>Microsoft MacBU <a href="http://www.schwieb.com/blog/2008/05/13/mac-office-2008-sp1/">announced</a> the availability of Office 2008 SP1 today in conjunction with the security patch. The <a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=395D1487-A3A6-4106-A0F8-4D6E1D6D89D2&amp;displaylang=en">180MB download</a> contains over 1,000 fixes including – what apparently was a major annoyance – the return of custom error bars and axis tick manipulation in Excel charts.</p>
<p>The full <a href="http://support.microsoft.com/kb/952331/en-us">release notes</a> are available for your perusal. Here are some other SP1 highlights:</p>
<p><b>Microsoft Office Excel</b></p>
<ul>
<li>Compatibility. Improved compatibility with files exchanged between Excel 2008 for Mac and Excel 2003 and Excel 2007 for Windows</li>
<li>Custom Error Bars. Restored formatting option on the Error Bars panel for data series</li>
<li>Printing. More reliable printing for elements on Excel 2008 workbooks</li>
</ul>
<p><strong>Microsoft Entourage</strong></p>
<ul>
<li>Calendar. Significant enhancements to improve calendar view and all-day reminders with reoccurrence</li>
<li>Exchange Server support. Overall improvement to synchronization support, including removing attachments from Exchange Server messages and synchronizing to the server, as well as support for editing the contents of Exchange Server messages via AppleScript and synchronizing the changes to the server</li>
<li>E-mail images. Ability to send and view images in Entourage from third-party tools</li>
</ul>
<p><strong>Microsoft Office Word</strong></p>
<ul>
<li>Printing. Improved accuracy when orienting tables with cell shading</li>
<li>Document map. Improved reliability and responsiveness to select items</li>
<li>Notebook layout. Updated formatting, recording status and a variety of display options</li>
</ul>
<p><strong>Microsoft Office PowerPoint</strong></p>
<ul>
<li>Printing. Improvements to eliminate crashing when printing documents to high-dpi printers and increased overall printing speed by 10 times on some large presentations</li>
<li>Mobile viewing. Ability to view Mac .PPTX files on Windows Mobile phones</li>
<li>AppleScript. Ability to use the PowerPoint selection object in AppleScript to implement custom scripts that operate on the current selection in PowerPoint</li>
</ul>
<h3>Restoring Functionality (&amp; Vulnerabilities)</h3>
<p>Microsoft&#8217;s MacBU also <a>announced</a> (official <a href="http://www.microsoft.com/presspass/press/2008/may08/05-13MacBU2008PR.mspx">press release</a>) the return of Visual Basic for Applications (VBA) support to the next major release of Office for Mac. This is a mixed bag since VBA macros are a juicy vector for vulnerabilities but that same functionality is critical to many business processes that have been developed using the suite.</p>
<p>From the announcement:</p>
<blockquote><p>Sharing information with customers as early as possible continues to be a priority for the Mac BU to allow customers to plan for their software needs.2 Although the Mac BU increased support in Office 2008 with alternate scripting tools such as Automator and AppleScript — and also worked with MacTech Magazine to create a reference guide, available at http://www.mactech.com/vba-transition-guide — the team recognizes that VBA-language support is important to a select group of customers who rely on sharing macros across platforms. The Mac BU is always working to meet customers’ needs and already is hard at work on the next version of Office for Mac.</p></blockquote>
<p><b>When</b> you install the security update or try out SP1, drop a note in the comments with your experiences and definitely let us and the MacBU know if they didn&#8217;t fix any of the issues you were having pre-SP1. Also, if you have any thoughts on the revival of VBA for Mac Office make sure to let us know in the comments as well.</p>
<p>(post updated to fix version errors &amp; links)</p>
<p><strong>Related research and analysis from GigaOM Pro:</strong><br />Subscriber content. <a href="http://pro.gigaom.com/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171405+microsoft-patches-office-commits-to-vba-support&utm_content=hrbrmstr">Sign up for a free trial</a>.</p><ul><li><a href="http://pro.gigaom.com/2011/02/content-farms-the-players-the-benefits-the-risks/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171405+microsoft-patches-office-commits-to-vba-support&utm_content=hrbrmstr">Content Farms: The Players, The Benefits, The&nbsp;Risks</a></li><li><a href="http://pro.gigaom.com/2011/03/why-ipad-2-will-lead-consumers-into-the-post-pc-era/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171405+microsoft-patches-office-commits-to-vba-support&utm_content=hrbrmstr">Why iPad 2 Will Lead Consumers Into the Post-PC&nbsp;Era</a></li><li><a href="http://pro.gigaom.com/2011/03/the-near-term-evolution-of-social-commerce/?utm_source=apple&utm_medium=editorial&utm_campaign=auto3&utm_term=171405+microsoft-patches-office-commits-to-vba-support&utm_content=hrbrmstr">The Near-Term Evolution of Social&nbsp;Commerce</a></li></ul><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=gigaom.com&amp;blog=14960843&amp;post=171405&amp;subd=gigaom2&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://gigaom.com/apple/microsoft-patches-office-commits-to-vba-support/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a08d08f6b541441fccf36bc6392a0784?s=96&#38;d=retro&#38;r=PG" medium="image">
			<media:title type="html">hrbrmstr</media:title>
		</media:content>

		<media:content url="http://gigapple.files.wordpress.com/2008/05/office2008macbox.png" medium="image" />
	</item>
	</channel>
</rss>
