Got a tip for us? Share it...

Apple Releases Security Update 2009-004 for Leopard and Tiger


Apple today released Security Update 2009-004 for both Mac OS X Leopard and Tiger via Software Update and Apple's downloads page. The release comes just one week after the release of Mac OS X 10.5.8 and Tiger Security Update 2009-003.

- Security Update 2009-004 (Leopard) (166 MB)

- Security Update 2009-004 (Tiger Intel) (166 MB)
- Security Update 2009-004 (Tiger PPC) (130 MB)
- Security Update 2009-004 (Server Tiger Universal) (204 MB)
- Security Update 2009-004 (Server Tiger PPC) (130.97 MB)

According to the associated security support document, the update addresses a vulnerability in the BIND suite of Unix utilities that works with the Domain Name System (DNS). There is reportedly a public exploit of the vulnerability in "wide circulation" at this time.

Top Rated Comments

(View all)

33 months ago
Just received the notification in my inbox, also verified that the patch is available now via Software Update.

Size on my early 2008 MBP is 10.1 MB (running 10.5.8).
Rating: 0 Positives / 0 Negatives
33 months ago
Yep. I can confirm it is there and am downloading now. That's like 1000 updates in like two weeks Apple. Thanks, but slow down. Looks like they want to make Leopard as perfect as possible before Snow Leopard.
Rating: 0 Positives / 0 Negatives
33 months ago
According to the Apple bulletin, this appears to resolve the BIND DNS vulnerability noted in CVE-2009-0696.
Rating: 0 Positives / 0 Negatives
33 months ago
Everything downloaded and installed fine. Installation went through in 10 seconds and everything works fine.
Rating: 0 Positives / 0 Negatives
33 months ago
Got the notification, but not seeing it in SUS, which is a pain. Scheduled my servers to go down for 2009-003 today from 4PM to 5PM. All patched, and now I get a notification that 2009-004 is out. Bitches! :o

NOTE: This is really a non-patch unless you're running Mac OS X Server and providing DNS.

I'd be more interested in Apple fixing the **** they broke on 10.5.8 Server patch that made the SN daemon freak out and lock the server if you have 2 NICs.
Rating: 0 Positives / 0 Negatives
33 months ago
NOW they're available to my Software Update Server. /elbow to throat!
Rating: 0 Positives / 0 Negatives
33 months ago
Like i said earlier...update crazy this past week and a half
Rating: 0 Positives / 0 Negatives
33 months ago
Everything downloaded and installed fine and fast. Looks good. Apple needs to slow down a bit with the updates. But they are just trying to make Leopard as good as possible before Snow Leopard.
Rating: 0 Positives / 0 Negatives
33 months ago
From the description of the exploit, it appears to only affect DNS Servers, and causes a server crash. Most people won't be affected by this. Still nice to see problems getting fixed.

jW
Rating: 0 Positives / 0 Negatives
33 months ago

Just received the notification in my inbox, also verified that the patch is available now via Software Update.

Wait... How do you get software update notifications in your inbox?
Rating: 0 Positives / 0 Negatives

[ Read All Comments ]