Apple updates Snow Leopard, fixes 69 flaws
The latest version of Snow Leopard includes a wide-reaching set of security fixes for OS X 10.6 and 10.5 users.

Apple's latest update to its Leopard and Snow Leopard operating systems brings with it a total of 69 security fixes many of them labelled as critical.
The company rolled out Mac OS X 10.6.3 yesterday, and with it issued Security Update 2010-002 for existing users of both client and server versions of OS X 10.6 Snow Leopard and OS X 10.5 Leopard. The security update is already incorporated in OS X 10.6.3.
According to the release notes, 69 security-related changes have been made in total across the various versions of the OS.
QuickTime alone is responsible for nine of the fixes, including addressing a heap buffer overflow in the program's handling of movies encoded in H.263, H.261, RLE, M-JPEG, FLC and MPEG formats, and dealing with memory corruptions in QuickTime's handling of H.264 and Sorenson movie files.
Many of the other security fixes to Snow Leopard apply solely to server-related components such as Wiki Server, Apache and iChat Server.
Separate patches are included for many of the open-source and UNIX components in Mac OS X, including PHP, MySQL and Ruby.
In addition to the QuickTime fixes for issues that could leave the door open for maliciously crafted movie files, CoreImage and ImageIO fixes beef up the OS' defences against malicious image files.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Aside from the security fixes, OS 10.6.3 brings with it a number of usability and performance tweaks too.
Users should see improved wireless networking performance including better Wi-Fi security, fixes for sleep/wake issues when connected with Wi-Fi and better wireless Time Machine backups to a Time Capsule.
The update also improves compatibility with OpenGL-based applications, boosts printing reliability and reliability of third-party USB input devices, resolves issues with recurring events in iCal when connected to an Exchange server.
Apple has also adjusted its Crash Reporter mechanism for reporting application and system crashes. When clicking on the Send to Apple button, not only will the system now send Crash Reporter state data, but also information on the applications and hardware devices connected to your Mac as well as recent system log info.
This simply automates the sending of information which is requested by Apple anyway when it follows up a crash report, with the company insisting it is completely anonymous.
Apple has issued detailed release notes on both the OS X 10.6.3 update and Security Update 2010-002, which include instructions for downloading and installing the updates.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd
-
Microsoft defends “negligent” security approach that prolonged vulnerability fix for five months
News The tech giant has refuted claims that its practices have left customers “in the dark”
By Ross Kelly
-
Ubuntu shifts to four-week update cycle
News Critical fixes will also come every two weeks, mitigating the issues involved with releasing prompt patches on the old three-week cadence
By Richard Speed
-
Microsoft angers admins as April Patch Tuesday delivers password feature without migration guidance
News Security fixes include a zero day exploited by a ransomware group and seven critical flaws
By Connor Jones
-
Motorola begins Stagefright patch roll-out
News 22 devices will be patched against the bug
By Jane McCallion
-
Google Chrome has highest number of vulnerabilities
News But the high level is down to its efficient detection system
By Clare Hopping
-
Microsoft's July Patch Tuesday to feature 2 critical fixes
News Microsoft has notified users of upcoming security fixes, including two critical-rated vulnerabilities
By Alex Hamilton
-
Apple issues Oracle Java 7 patch for Mac OS X users
News Consumer electronics giant hopes patch will fix zero-day Java exploit in Mac OS X.
By Rene Millman
-
Oracle issues ‘huge’ patch update
News A whopping 78 vulnerabilities are addressed in Oracle's latest CPU.
By Tom Brewster