Mac update plugs 28 flaws, does not include Flash 10.1

Apple on Tuesday released its fourth Mac OS X security update of the year to plug 28 vulnerabilities.

The update to version 10.6.4 addresses flaws in 17 components, some open-source, including CUPS, iChat, Network Authorization, SquirrelMail, Ruby, Wiki Server and Flash Player. Successful exploit of many of the bugs could lead to arbitrary code execution.

While the patch bundle does address two Flash vulnerabilities, it does not update users to the latest version of the popular multimedia software, 10.1, which was released last week. Instead, the Mac update includes Flash version 10.0.45.2.

Adobe's Wendy Poland, in a blog post Tuesday, said that while the Mac update does not appear to downgrade users who already have upgraded to the latest version of Flash, users are encouraged to verify they are running the correct edition. If they are not, they should install it.

Meanwhile, Mac users should install the new update via their Software Update preferences or through the Apple Downloads page.

More in News

Privacy-bolstering "Apps Act" introduced in House

The bill would provide consumers nationwide with similar protections already enforced by a California law.

Microsoft readies permanent fix for Internet Explorer bug used in energy attacks

Microsoft is prepping a whopper of a security update that will close 33 vulnerabilities, likely including an Internet Explorer (IE) flaw that has been used in targeted website attacks against the U.S. government.

Weakness in Adobe ColdFusion allowed court hackers access to 160K SSNs

Up to 160,000 Social Security numbers and one million driver's license numbers may have been accessed by intruders.