Apple Releases Security Update 2009-004 for Leopard and Tiger

Apple today released Security Update 2009-004 for both Mac OS X Leopard and Tiger via Software Update and Apple's downloads page. The release comes just one week after the release of Mac OS X 10.5.8 and Tiger Security Update 2009-003.
- Security Update 2009-004 (Leopard) (166 MB)
- Security Update 2009-004 (Tiger Intel) (166 MB)
- Security Update 2009-004 (Tiger PPC) (130 MB)
- Security Update 2009-004 (Server Tiger Universal) (204 MB)
- Security Update 2009-004 (Server Tiger PPC) (130.97 MB)
According to the associated security support document, the update addresses a vulnerability in the BIND suite of Unix utilities that works with the Domain Name System (DNS). There is reportedly a public exploit of the vulnerability in "wide circulation" at this time.
Top Rated Comments
(View all)33 months ago
Just received the notification in my inbox, also verified that the patch is available now via Software Update.
Size on my early 2008 MBP is 10.1 MB (running 10.5.8).
Size on my early 2008 MBP is 10.1 MB (running 10.5.8).
33 months ago
Yep. I can confirm it is there and am downloading now. That's like 1000 updates in like two weeks Apple. Thanks, but slow down. Looks like they want to make Leopard as perfect as possible before Snow Leopard.
33 months ago
According to the Apple bulletin, this appears to resolve the BIND DNS vulnerability noted in CVE-2009-0696.
33 months ago
Everything downloaded and installed fine. Installation went through in 10 seconds and everything works fine.
33 months ago
Got the notification, but not seeing it in SUS, which is a pain. Scheduled my servers to go down for 2009-003 today from 4PM to 5PM. All patched, and now I get a notification that 2009-004 is out. Bitches! :o
NOTE: This is really a non-patch unless you're running Mac OS X Server and providing DNS.
I'd be more interested in Apple fixing the **** they broke on 10.5.8 Server patch that made the SN daemon freak out and lock the server if you have 2 NICs.
NOTE: This is really a non-patch unless you're running Mac OS X Server and providing DNS.
I'd be more interested in Apple fixing the **** they broke on 10.5.8 Server patch that made the SN daemon freak out and lock the server if you have 2 NICs.
33 months ago
Everything downloaded and installed fine and fast. Looks good. Apple needs to slow down a bit with the updates. But they are just trying to make Leopard as good as possible before Snow Leopard.
33 months ago
From the description of the exploit, it appears to only affect DNS Servers, and causes a server crash. Most people won't be affected by this. Still nice to see problems getting fixed.
jW
jW
33 months ago
Just received the notification in my inbox, also verified that the patch is available now via Software Update.
Wait... How do you get software update notifications in your inbox?[ Read All Comments ]

Analytics firm Chitika today released a report showing that by its metrics iOS has now surpassed OS X in overall web traffic share in the United States. Chitika's methodology involves an analysis...
One of the most frequent reasons for an iPhone to go on a trip to the Apple Store's Genius Bar is because of water damage. Typically, a water damaged iPhone can be replaced for a flat $199...
TheVerge's Joshua Topolsky summarizes the iPad 3 casing findings reported earlier today, but also adds his own sources regarding some details of the iPad 3.
Image from RepairLabs
As...
Last July, Apple discontinued the white MacBook from its consumer lineup, pushing consumers toward the company's popular MacBook Air line or the 13-inch MacBook Pro. The company didn't kill...
Popular iPhone Twitter client Tweetbot has finally arrived on the iPad, with a user interface instantly familiar to any current Tweetbot user. Designed for the Twitter power-user, Tweetbot packs a...