Apple releases Security Update 2010-006 (Snow Leopard)

Apple today released Security Update 2010-006 (Snow Leopard) which is recommended for all users and improves the security of Mac OS X.

Security Update 2010-006

• AFP

CVE-ID: CVE-2010-1820

Available for: Mac OS X v10.6.4, Mac OS X Server v10.6.4

Impact: A remote attacker may access AFP shared folders without a valid password

Description: An error handling issue exists in AFP Server. A remote attacker with knowledge of an account name on a target system may bypass the password validation and access AFP shared folders. By default, File Sharing is not enabled. This issue does not affect systems prior to Mac OS X v10.6. Credit to Richard Noll for reporting this issue.

Security Update 2010-006 (Snow Leopard) is available via Software Update and also as a standalone installer.

More info and download link (1.93MB) here.

12 Comments

  1. No worries…

    But a real stink is the widespread click/ping trackers, web bugs, hidden Flash cookies etc., that Apple is allowing to occur with Safari, despite private browsing mode being turned on.

    Do you know there is currently about 300 web bugs tracking your every move on line and their numbers are growing rapidly?

    Read the Wall Street Journal story over on Slashdot, your kids are in some peril with strangers monitoring their web use.

  2. @grh

    http://www.apple.com/feedback/

    or

    http://www.apple.com/feedback/macosx.html

    There is a bug report option there for OS X.

    The main problem Apple has when a regular user has a real exploit on their hands is being able to communicate that to Apple in a effective manner. Being able to show them or send them the malware. Most times they will just think something is wrong with the user or their machine, not a real vulnerability.

    I came across a nasty one and had a hell of a time being able to communicate this over to Apple, they are used to working with people who are knowledgeable about finer details of OS X and the security community at large, not just users who came across a exploit and want to report it.

    So the only thing I can suggest is find yourself a intermediary that can test your problem and rule out, user or other failure, perhaps a top level Apple Genius, explain first you suspect malware so they take precautions and not let it infect other systems or their networks.

    And don’t send the malware to S jobs, you’ll be in a lot of trouble.

  3. @Bizzarro.

    Private browsing is not there to protect your privacy from the parties you contact on the web during your online session.

    It’s there to protect your privacy from other people who have access to your computer while you’re not online anymore. Always was.

  4. Thanks to Bizzarro, AAPLguy and jafo. Anyone interested in why I asked — my broadband provider insists either my iMac has/had some malware or there was/is a bug in my ADSL modem. They referred me to this

    http://thenextweb.com/us/2010/02/22/chuck-norris-virus-roundhouse-kicks-unprotected-routers/

    I’m still researching what it is/was that caused my combination iMac/modem to undertake huge data transfer rates, up and down, without me at the wheel.

    Anyone interested to comment or help privately, <loloveweb@hotmail.com>

  5. @bizarro…i don’t think you understand what private browsing does. it’s nothing to do with security protection from sites you visit.

    what is your source for saying over 300 bugs tracking every move on a Mac?

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.