Linked by Thom Holwerda on Sat 13th May 2006 22:03 UTC
Mac OS X Apple's security update train rumbled into the station late May 11 with fixes for a whopping 43 Mac OS X and QuickTime vulnerabilities. The company's Security Update 2006-003 patches 31 flaws in the Mac OS X, most of them serious enough to cause 'arbitrary code execution attacks'. Apple also shipped QuickTime 7.1 as a major security overhaul to correct 12 code execution and denial-of-service flaws.
Thread beginning with comment 124478
To view parent comment, click here.
To read all comments associated with this story, please click here.
RE[2]: you know....
by JustAnotherMacUser on Sun 14th May 2006 15:09 UTC in reply to "RE: you know...."
JustAnotherMacUser
Member since:
2006-01-08

Apple tracking them down?

Apple is abusing the Mac community to find all their flaws in Mac OS X and then fixing them afterwards, instead of using software/methods to stress test their code first.

How is it possible that one guy finds over a dozen vunerabilites at one time? in such a short period? What is he doing that Apple has failed to do?

Reply Parent Bookmark Score: 1

RE[3]: you know....
by spook on Sun 14th May 2006 15:12 in reply to "RE[2]: you know...."
spook Member since:
2006-01-09

Apple is abusing the Mac community to find all their flaws in Mac OS X and then fixing them afterwards, instead of using software/methods to stress test their code first.
==================================================

Can you tell me how Microsoft, Linux, Unix and others do it?

Cause I could be wrong here, but they all do it the same way

and as mentioned before, so of the fixes are not even for Apple programs


oh another url for you

http://www.dreamlight.com/insights/bugs/Apple/lookupd.html

Reply Parent Bookmark Score: 1

RE[4]: you know....
by JustAnotherMacUser on Sun 14th May 2006 15:26 in reply to "RE[3]: you know...."
JustAnotherMacUser Member since:
2006-01-08

I have had my /etc/hosts edited for this bug a long time ago.

Plus it wasn't the lookupd that was the trojaned process.

Reply Parent Bookmark Score: 1

RE[5]: you know....
by somebody on Sun 14th May 2006 16:46 in reply to "RE[3]: you know...."
somebody Member since:
2005-07-07

Apple is abusing the Mac community to find all their flaws in Mac OS X and then fixing them afterwards, instead of using software/methods to stress test their code first.
==================================================

Can you tell me how Microsoft, Linux, Unix and others do it?


Well, I can tell you at least one thing. What you said about Linux.

[a bit of sarcasm] Linux was made by the same community that is fixing it. So how could you for example abuse your self? (I can't think of anything else, but the case where you would forcefully sit on the pointy object, but this wouldn't be abuse you talk about) [/a bit of sarcasm]

community can't abuse it self, but if it can enlighten me please. In Apple, MS case product is made by company, in Linux case it is made by community. IBM, Novell, RH are just players that are using it (and helping fixing it too, just look at their track records) they're not THE ONES WHO MADE LINUX

Edited 2006-05-14 16:50

Reply Parent Bookmark Score: 0