Apple Security Update 2005-002
Submitted by boredatwork on Wed, 02/23/2005 - 07:03
Tagged:
This is only for Mac OS X 10.3.4 or later.
For information about the update go to Apple HERE.
By Peter Cohen MacCentral
Apple on Tuesday released Security Update 2005-002. This update covers installations of Mac OS X that use Java 1.4.2. The update is available for download through the Software Update system preference pane, and is also available for download from Apple's Web site.
According to information posted on Apple's Web site, this update corrects an issue "where an untrusted applet could gain elevated privileges and potentially execute arbitrary code."
Apple describes the problem as related to a vulnerability in the Java plug-in. The exploit works through JavaScript "calling into Java code, including reading and writing files with the privileges of the user running the applet. Releases prior to Java 1.4.2 on Mac OS X are not affected by this vulnerability."
Further information about this vulnerability is available in Document ID 57591 from Sun.
Apple's update makes changes to the following files:
Java Web Start
JavaPluginCocoa.bundle
JavaScriptCore
Core Java classes







Recent comments
22 weeks 2 days ago
22 weeks 2 days ago
24 weeks 6 days ago
25 weeks 4 days ago
25 weeks 4 days ago
25 weeks 4 days ago
30 weeks 1 day ago
30 weeks 2 days ago
30 weeks 5 days ago
31 weeks 6 hours ago