Apple updates Leopard, issues 68 fixes

But it doesn't patch three iCal security bugs

More than three months after it last updated Mac OS X, Apple Wednesday released 10.5.3, an upgrade for its Leopard operating system that boasts nearly 70 stability, compatibility and security improvements and fixes.

Apple did not include patches for several iCal vulnerabilities in the update, however.

Mac OS X 10.5.3, the third upgrade to Leopard since Apple launched the current in October 2007, addresses issues in several components and bundled applications, ranging from the Address Book and Automator to Time Machine and VoiceOver.

Apple also listed a baker's dozen under a "General" category that included a fix for hard drives that wouldn't show in the Finder; an improvement in Spotlight, the OS's built-in search tool, for searches done on AFP volumes; and a patch for stuttering audio and video playback from certain USB-based hardware.

AirPort, Apple's label for its wireless technology, got a pair of fixes: one to improve wireless reliability in general, the other to boost reliability when used with the company's relatively new Time Capsule router-cum-backup-device that debuted earlier this year.

iChat, the Mac OS's bundled instant messaging and video conferencing application, received five fixes; Mail, Apple's own e-mail client, got 10; and Time Machine was the target of seven.

The Time Machine fixes, said Apple, resolve issues when backing up a notebook running on battery power, and address a reliability problem some users have encountered when restoring from a Time Machine backup.

Apple also tucked eight fixes for iCal, its personal scheduling program, into the 10.5.3 update, but did not patch the three security vulnerabilities disclosed a week ago by Core Security Technologies.

The three iCal bugs, which were reported to Apple in January 2008, were revealed last Wednesday by Core after it had repeatedly been asked by Apple to delay publishing its findings. Core decided to unveil the vulnerabilities after Apple again postponed its patches.

"No vendor moves as fast as the vulnerability researcher wants them to," said Andrew Storms, director of security operations at nCircle Network Security.

Storms refused to blame either side. "It generally takes a major vendor, like Microsoft or Apple, about six to eight months to get a patch released," he said. "But Core had every right to push the vendor into delivering the patch."

In a follow-on interview last week, Ivan Arce, Core Technologies' chief technology officer, said that the current version of iCal is vulnerable to the flaws, one of which he considered critical. But his team had not found evidence of any in-the-wild attacks trying to trigger the iCal vulnerabilities.

"It wouldn't take a whole lot of reverse engineering to figure this out," Storms said, referring to the ease with which attackers would be able to put two and two together from Core's disclosures. "It's a valid concern," he added. "The moment you click on a malformed .ics file, you're done."

Apple has not responded to e-mails asking when it would patch the iCal vulnerabilities.

Mac OS X 10.5.3 can be downloaded manually from the Apple site, or retrieved and installed using Mac OS X's integrated update feature.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.
Gregg Keizer

Gregg Keizer

Computerworld
Show Comments

Cool Tech

Toys for Boys

Family Friendly

Stocking Stuffer

SmartLens - Clip on Phone Camera Lens Set of 3

Learn more >

Christmas Gift Guide

Click for more ›

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Aysha Strobbe

Microsoft Office 365/HP Spectre x360

Microsoft Office continues to make a student’s life that little bit easier by offering reliable, easy to use, time-saving functionality, while continuing to develop new features that further enhance what is already a formidable collection of applications

Michael Hargreaves

Microsoft Office 365/Dell XPS 15 2-in-1

I’d recommend a Dell XPS 15 2-in-1 and the new Windows 10 to anyone who needs to get serious work done (before you kick back on your couch with your favourite Netflix show.)

Maryellen Rose George

Brother PT-P750W

It’s useful for office tasks as well as pragmatic labelling of equipment and storage – just don’t get too excited and label everything in sight!

Cathy Giles

Brother MFC-L8900CDW

The Brother MFC-L8900CDW is an absolute stand out. I struggle to fault it.

Luke Hill

MSI GT75 TITAN

I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?