Apple has released Security Update 2010-003 (Leopard-Client) to address a critical vulnerability in the way Apple Type Services in Mac OS X 10.6 Snow Leopard parses embedded fonts. Users who view or download any documents containing maliciously crafted embedded fonts run a risk of arbitrary code execution. The update addresses this issue by improving index checking. This vulnerability was first demonstrated by Charlie Miller at the Pwn2Own conference 20 days ago, which shows a reasonably quick response on Apple's part. A nearly identical update - Security Update 2010-003 (Leopard-Server) - that eliminates the same vulnerability is available for Leopard Server. The update requires you are running Mac OS X 10.5.8 and is available via Software Update and the Apple Support Downloads page. (Free, 218.6/379.5 MB)
Thoughtful, detailed coverage of the Mac, iPhone, and iPad, plus the best-selling Take Control ebooks.
Use Shift to Compare Edits in iPhoto '08
In iPhoto '08, while you're editing a photo, press the Shift key to see a "before" view; let it up to see the "after" view. It's much faster and easier than using Undo and Redo.
Written by
Adam C. Engst
Security Update 2010-003 (Leopard)
Get more productive with software from Smile: PDFpen forediting PDFs; TextExpander for saving time and keystrokes while you
type; DiscLabel for designing CD/DVD labels and inserts. Free demos,
fast and friendly customer support. <http://www.smilesoftware.com/>
