Software Update time- Security Update 2005-002 Released


Apple today released Security Update 2005-002 via the Software Update utility in Mac OS X. The update offers numerous security enhancements as well as a few updated components, including Java Web Start, JavaPluginCocoa.bundle, JavaScriptCore, and Core Java classes. Apple says in the release that the update addresses an issue where an untrusted applet could gain elevated privileges in the system and potentially execute arbitrary code: “A vulnerability in the Java Plug-in may allow an untrusted applet to escalate privileges, through JavaScript calling into Java code, including reading and writing files with the privileges of the user running the applet. Releases prior to Java 1.4.2 on Mac OS X are not affected by this vulnerability.” It’s good to know Apple is addressing these security concerns, with previous complaints by security firms that Apple was not acting fast enough. As the name implies, this is Apple’s second security update of the new year.

Comments are closed.