The megapatch, also known as Mac OS X 10.4.9, is the seventh Apple security patch release in three months. It deals with vulnerabilities in Apple"s own software, as well as third-party components such as Adobe Systems" Flash Player, OpenSSH and MySQL. Sixteen of the vulnerabilities addressed by the update were previously released as part of two high-profile bug-hunting campaigns. Several of the flaws could be exploited to gain full control over a Mac running the vulnerable component, according to Apple"s advisory. Other holes are limited and could only be exploited to crash a Mac or used by somebody who already has access to a machine.
Eight vulnerabilities are related to the way Mac OS X handles disk images; mounting a malicious image may lead to an error and could provide a means for an attacker to breach a Mac, Apple said. Nine vulnerabilities were released as part of the Month of Apple Bugs in January and seven bugs disclosed in the Month of Kernel Bugs in November. While several of the vulnerabilities repaired by Apple"s updates were previously known, it doesn"t appear that any attacks that exploited the flaws actually occurred. Apple also issued a second update which fixes a security bug in iPhoto that could allow an attacker to craft a malicious "photocast" which, when opened, could compromise a Mac.