Security Update 2007-009がソフトウェア・アップデート経由で出ています。
Security Update 2007-009 1.0 35.4 MB以下、Apple Product Securityからのメールを引用…しようとしたけど、内容が多すぎるので項目のみ引用。
すべてのユーザに、Security Update 2007-009 の適用を推奨します。このアップデートでは、次のコンポーネントでの信頼性とセキュリティの強化が行われます。
Core Foundation
CUPS
Flash Player Plug-in
Launch Services
perl
python
クイックルック
ruby
Safari
Samba
Shockwave Plug-in
Spin Tracer
このアップデートの詳細については、こちらを参照してください: http://docs.info.apple.com/article.html?artnum=61798-ja
APPLE-SA-2007-12-17 Security Update 2007-009
Security Update 2007-009 is now available and addresses the following issues:
Address Book
CVE-ID: CVE-2007-4708
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11
CFNetwork
CVE-ID: CVE-2007-4709
Available for: Mac OS X v10.5.1, Mac OS X Server v10.5.1
ColorSync
CVE-ID: CVE-2007-4710
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11
Core Foundation
CVE-ID: CVE-2007-5847
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11
CUPS
CVE-ID: CVE-2007-5848
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11
CUPS
CVE-ID: CVE-2007-4351
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.1, Mac OS X Server v10.5.1
CUPS
CVE-ID: CVE-2007-5849
Available for: Mac OS X v10.5.1, Mac OS X Server v10.5.1
Desktop Services
CVE-ID: CVE-2007-5850
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11
Flash Player Plug-in
CVE-ID: CVE-2007-5476
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.1, Mac OS X Server v10.5.1
GNU Tar
CVE-ID: CVE-2007-4131
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11
iChat
CVE-ID: CVE-2007-5851
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11
IO Storage Family
CVE-ID: CVE-2007-5853
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11
Launch Services
CVE-ID: CVE-2007-5854
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.1, Mac OS X Server v10.5.1
Launch Services
CVE-ID: CVE-2007-6165
Available for: Mac OS X v10.5.1, Mac OS X Server v10.5.1
CVE-ID: CVE-2007-5855
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.1, Mac OS X Server v10.5.1
perl
CVE-ID: CVE-2007-5116
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.1, Mac OS X Server v10.5.1
python
CVE-ID: CVE-2007-4965
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.1, Mac OS X Server v10.5.1
Quick Look
CVE-ID: CVE-2007-5856
Available for: Mac OS X v10.5.1, Mac OS X Server v10.5.1
Quick Look
CVE-ID: CVE-2007-5857
Available for: Mac OS X v10.5.1, Mac OS X Server v10.5.1
ruby
CVE-ID: CVE-2007-5770
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.1, Mac OS X Server v10.5.1
ruby
CVE-ID: CVE-2007-5379, CVE-2007-5380, CVE-2007-6077
Available for: Mac OS X v10.5.1, Mac OS X Server v10.5.1
Safari
CVE-ID: CVE-2007-5858
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.1, Mac OS X Server v10.5.1
Safari RSS
CVE-ID: CVE-2007-5859
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11
Samba
CVE-ID: CVE-2007-4572, CVE-2007-5398
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.1, Mac OS X Server v10.5.1
Shockwave Plug-in
CVE-ID: CVE-2006-0024
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.1, Mac OS X Server v10.5.1
SMB
CVE-ID: CVE-2007-3876
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11
Software Update
CVE-ID: CVE-2007-5863
Available for: Mac OS X v10.5.1, Mac OS X Server v10.5.1
Spin Tracer
CVE-ID: CVE-2007-5860
Available for: Mac OS X v10.5.1, Mac OS X Server v10.5.1
Spotlight
CVE-ID: CVE-2007-5861
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11
tcpdump
CVE-ID: CVE-2007-1218, CVE-2007-3798
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11
XQuery
CVE-ID: CVE-2007-1659, CVE-2007-1660, CVE-2007-1661, CVE-2007-1662, CVE-2007-4766, CVE-2007-4767, CVE-2007-4768
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11
Security Update 2007-009 may be obtained from the Software Update pane in System Preferences, or Apple's Software Downloads web site: http://www.apple.com/support/downloads/
For Mac OS X v10.5.1
The download file is named: "SecUpd2007-009.dmg"
Its SHA-1 digest is: 9d1743b2cd15f3934d82cc6341c3142a3d16becf
For Mac OS X v10.4.11 (Universal)
The download file is named: "SecUpd2007-009Univ.dmg"
Its SHA-1 digest is: ac07f4850b812af0761f859bb4d63c2e0f2a6113
For Mac OS X v10.4.11 (PPC)
The download file is named: "SecUpd2007-009Ti.dmg"
Its SHA-1 digest is: 2e75b99b1a10fb973807cba14b99080da38ad288
Information will also be posted to the Apple Security Updates web site: http://docs.info.apple.com/article.html?artnum=61798