Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

FYI Warning: Security update and Rosetta

Macintouch is reporting that the recent security update for Snow Leopard is preventing printing from PPC applications such as Quicken snd AppleWorks, and in some cases is preventing them running at all.


http://www.macintouch.com/readerreports/snowleopard/index.html#d02feb2012

24 inch iMac-OTHER, Mac OS X (10.6.8), 13 inch Macbook Pro (10.6.8)

Posted on Feb 2, 2012 8:55 AM

Reply
26 replies

Feb 4, 2012 6:28 AM in response to Roger Wilmut1

What I still want to know is since v1.1. reportedly removed the patches in the original for the three ImageIO vulnerabilities as the fix for the Rosetta problem, doesn't that leave us wide open now for those exploits? These looked kind of nasty. Nothing like having a little information about what's going on. EDIT: I'm making this a separate post in order to get the most possible attention to this issue.


  • ImageIO

    Available for: Mac OS X v10.6.8, Mac OS X Server v10.6.8

    Impact: Viewing a maliciously crafted TIFF file may lead to an unexpected application termination or arbitrary code execution

    Description: A buffer overflow existed in ImageIO's handling of CCITT Group 4 encoded TIFF files. This issue does not affect OS X Lion systems.

    CVE-ID

    CVE-2011-0241 : Cyril CATTIAUX of Tessi Technologies

  • ImageIO

    Available for: Mac OS X v10.6.8, Mac OS X Server v10.6.8, OS X Lion v10.7 to v10.7.2, OS X Lion Server v10.7 to v10.7.2

    Impact: Viewing a maliciously crafted TIFF file may lead to an unexpected application termination or arbitrary code execution

    Description: A buffer overflow existed in libtiff's handling of ThunderScan encoded TIFF images. This issue is addressed by updating libtiff to version 3.9.5.

    CVE-ID

    CVE-2011-1167

ImageIO

Available for: Mac OS X v10.6.8, Mac OS X Server v10.6.8, OS X Lion v10.7 to v10.7.2, OS X Lion Server v10.7 to v10.7.2

Impact: Multiple vulnerabilities in libpng 1.5.4

Description: libpng is updated to version 1.5.5 to address multiple vulnerabilities, the most serious of which may lead to arbitrary code execution. Further information is available via the libpng website at http://www.libpng.org/pub/png/libpng.html


Message was edited by: WZZZ

Feb 24, 2012 12:37 PM in response to baltwo

a brody: Maybe so. The only confirmation that I have seen that the problem is fixed was limited to one powerpc application. Supporting your conclusion is the case that the same app (PrintSmith) does work on another Snow Leopard machine with all the same updates.


baltwo: I already reininstalled Snow Leopard and all missing updates before posting here.

FYI Warning: Security update and Rosetta

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.