After taking guff in the press for a while for its lack of a patch for the famous recent DNS bug, Apple has finally issued a patch. The update it comes in also patches 16 other vulnerabilities:

- Open Scripting ArchitecturePrivilege elevation bug when loading plug-ins.
- CarbonCoreA stack overflow in handling long file names. Potential code execution.
- CoreGraphicsTwo bugs, both code execution, one for malicious graphics, the other for malicious PDFs.
- Data Detectors EngineEngine may crash when parsing maliciously crafted content.
- Disk UtilityA local user may obtain System privileges.
- OpenLDAPAn ASN parsing bug can lead to a crash.
- OpenSSLA range checking error from last September (Red Hat patched it in two weeks) can lead to remote code execution.
- PHPFive different bugs, the worst of which can lead to remote code execution.
- QuickLookA maliciously crafted Microsoft Office file can cause QuickLooks to crash or allow remote code execution.
- rsyncPath validation errors, which were also reported in 2007, are resolved.





