Site icon The Mac Security Blog

Apple Security Update 2014-002 Patches Secure Transport

Yesterday, Apple released Security Update 2014-002 for OS X with patches for 13 vulnerabilities.

This update is available for: OS X Lion v10.7.5, OS X Lion Server v10.7.5, OS X Mountain Lion v10.8.5, OS X Mavericks v10.9.2.

Unfortunately, Apple has stopped releasing security updates for Snow Leopard, the 2009 edition operating system.

MORE: What to Do if Your Mac Can’t Run OS X Mavericks 

The security-only update addresses multiple security flaws, including a vulnerability in its Secure Transport—Apple’s API mechanism for making SSL or TLS connections—that made it possible for “an attacker to establish two connections which had the same encryption keys and handshake, insert the attacker’s data in one connection, and renegotiate so that the connections may be forwarded to each other,” Apple noted.

Apple’s security advisory further described its impact, saying, “An attacker with a privileged network position may capture data or change the operations performed in sessions protected by SSL.” Apple credited members of the Prosecco research team at Inria Paris for reporting the flaw—Antoine Delignat-Lavaud, Karthikeyan Bhargavan and Alfredo Pironti.

In correlation with the release of Security Update 2014-002, Apple also patched its iOS and Apple TV implementations of Secure Transport with iOS 7.1.1 and Apple TV 6.1.1.

Security Update 2014-002 addresses the following vulnerabilities:

We strongly encourage all Mac users to download and install all security updates as soon as possible – it is an essential layer of security that keeps your digital life secure.

You can update through Apple’s Software Update tool by choosing Apple menu >Software Update when you’re ready to install, or you can go directly to Apple’s support page to download the updates from there.

For OS X Lion Server users, you can go here to download the 177.2 MB update.

OS X Lion users can go here to download the 126.9 MB update.

OS X Mountain Lion users can go here to download the 135.9 MB update.

OS X Mavericks users can go here to download the 80.5 MB update; this update also includes Safari 7.0.3.

Share this: