Apple plugs 88 Mac OS X security holes

Apple today released one of its biggest Mac OS X security updates in recent memory, covering a whopping 88 documented vulnerabilities.

The Mac OS X v10.6.3 update, which is considered "critical," covers flaws that could lead to remote code execution, information disclosure and denial-of-service attacks.

In some scenarios, a malicious hacker could take complete control of a Mac-powered machine if a user simply views a malicious image or movie file.

In another case, a Mac user running spell-check could have his/her machine hijacked by hackers.

The update covers critical vulnerabilities in AppKit, QuickTime,CoreMedia, CoreTypes, DiskImages, ImageIO and Image RAW.

It also covers holes in several open-source components, including Apache, ClamAV, MySQL, PHP.

Here's the full list of the patched vulnerabilities.

The Security Update 2010-002 / Mac OS X v10.6.3 may be obtained from the Software Update pane in System Preferences, or Apple's Software Downloads web page.

  • hurray for Apple

    its nice they are patching things up!

    while its "88" its bad form to call them security holes, a lot of the
    updates aren't really security issues, but plenty of them are.

    They call them security... because they can be related to security, not
    that they pose much of a threat. For example... one update is because
    ClamAV might not be able to update itself... not that it was directly a
    security hole or anything. It doesn't pretend to update and doesn't, it
    would just fail. A lot of others are things that only happen on certain
    OS versions if you have certain other 3rd party (non default) software

    so overall its great Apple is fixing problems, even 3rd party related
