Register FAQ / Rules Forum Spy Search Today's Posts Mark Forums Read
Go Back   MacRumors Forums > News and Article Discussion > MacRumors.com News Discussion

Reply
 
Thread Tools Search this Thread Display Modes
Old Feb 25, 2014, 12:08 PM   #1
MacRumors
macrumors bot
 
Join Date: Apr 2001
Apple Releases OS X 10.9.2 With Fix for Major SSL Vulnerability, FaceTime Audio




Apple today released OS X 10.9.2, which includes a fix for a major SSL security flaw that first came to light on Friday, after the release of iOS 7.0.6.

The bug, which was introduced in the form of a single line of errant code that allowed an attacker to bypass SSL/TLS verification routines, left OS X users vulnerable to a man-in-the-middle attack. Shared wired or wireless networks could allow an attacker to intercept communications on affected machines, acquiring sensitive information like login credentials and passwords, or injecting harmful malware.

Test on gotofail.com after updating to OS X 10.9.2
While the SSL vulnerability was first introduced to iOS in 2012, it only affects Macs running OS X 10.9. Lion and Mountain Lion users are not affected.

OS X 10.9.2 was first seeded to developers in December and has seen seven beta iterations since that time. Along with an emergency fix for the SSL bug, OS X 10.9.2 also includes FaceTime Audio, new blocking controls for iMessage and FaceTime, call waiting support for FaceTime, Mail fixes for bugs with fetching messages, AutoFill improvements, and several other bug fixes and general improvements.

It is recommended that all users running OS X 10.9 Mavericks upgrade to OS X 10.9.2 as soon as possible to disable the vulnerability.

- OS X Mavericks Update v10.9.2 (859.70 MB)
- OS X Mavericks Update v10.9.2 (Combo) (859.70 MB)

Alongside OS X 10.9.2, Apple has also released security updates for OS X Mountain Lion and Lion:

- Security Update 2014-001 (Mountain Lion) (115.8 MB)

- Security Update 2014-001 (Lion) (123.40 MB)
- Security Update 2014-001 Server (Lion) (173.60 MB)

Article Link: Apple Releases OS X 10.9.2 With Fix for Major SSL Vulnerability, FaceTime Audio
MacRumors is offline   0 Reply With Quote
Old Feb 25, 2014, 12:08 PM   #2
musika
macrumors 65816
 
musika's Avatar
 
Join Date: Sep 2010
Location: New York
Good. Should have been out four days ago.
__________________
I write about lots of things at turtlepie.net.
musika is offline   27 Reply With Quote
Old Feb 25, 2014, 12:09 PM   #3
PBF
macrumors 68030
 
Join Date: Jul 2005
Location: NYC
God, I hope it fixes the most annoying Safari bug where it loads a random page without finishing typing the URL.
PBF is offline   20 Reply With Quote
Old Feb 25, 2014, 12:09 PM   #4
Cyborg21
macrumors 6502
 
Join Date: Sep 2013
finally
__________________
Retina MacBook Pro 13-inch 2.6 ghz haswell with OS X Mavericks (10.9.2)
iPod Shuffle Space Gray 4th gen.
Cyborg21 is offline   3 Reply With Quote
Old Feb 25, 2014, 12:09 PM   #5
seble
macrumors 6502a
 
Join Date: Sep 2010
I hope it fixes odd window placement bugs and failing to wake from sleep. Oh and the weird 'your computer is out of memory' bug that my late 2012 iMac got last week... I'm checking this update careful Apple...
seble is offline   0 Reply With Quote
Old Feb 25, 2014, 12:10 PM   #6
Z400Racer37
macrumors 6502
 
Join Date: Feb 2011
Yes!!!! Facetime audioooooooo!!!!
Z400Racer37 is offline   21 Reply With Quote
Old Feb 25, 2014, 12:10 PM   #7
macintologist
macrumors regular
 
Join Date: May 2004
Facetime Audio support is amazing. Does anyone know what the Call waiting feature is?
macintologist is offline   2 Reply With Quote
Old Feb 25, 2014, 12:11 PM   #8
tarasis
macrumors 6502
 
Join Date: Oct 2007
Location: Here, there and everywhere
Curses, not the SW release I was hoping for
tarasis is offline   0 Reply With Quote
Old Feb 25, 2014, 12:11 PM   #9
bbfc
macrumors 68000
 
bbfc's Avatar
 
Join Date: Oct 2011
Location: Gosforth, England
FaceTime Audio is amazing!
bbfc is offline   3 Reply With Quote
Old Feb 25, 2014, 12:13 PM   #10
C DM
macrumors G3
 
Join Date: Oct 2011
Quote:
Originally Posted by musika View Post
Good. Should have been out four days ago.
Perhaps with a fix that caused some other issues or something like that, right?
C DM is offline   8 Reply With Quote
Old Feb 25, 2014, 12:13 PM   #11
sebastiann01
macrumors newbie
 
Join Date: Aug 2013
whoever said they usually come out around 1pm was spot on
sebastiann01 is offline   2 Reply With Quote
Old Feb 25, 2014, 12:13 PM   #12
Sky Blue
Guest
 
Join Date: Jan 2005
Looks like 1 version for all hardware? not a retina one and everything else?
Sky Blue is offline   0 Reply With Quote
Old Feb 25, 2014, 12:13 PM   #13
AngerDanger
macrumors 65816
 
AngerDanger's Avatar
 
Join Date: Dec 2008
Location: location, location!
Quote:
Originally Posted by MacRumors View Post
The bug, which was introduced in the form of a single line of errant code that allowed an attacker to bypass SSL/TLS verification routines, left OS X users vulnerable to a man-in-the-middle attack. Shared wired or wireless networks could allow an attacker to intercept communications on affected machines, acquiring sensitive information like login credentials and passwords, or injecting harmful malware.
Ah, yes, the man-in-the-middle attack…


Last edited by AngerDanger; Feb 25, 2014 at 12:20 PM.
AngerDanger is offline   12 Reply With Quote
Old Feb 25, 2014, 12:14 PM   #14
TsMkLg068426
In Time-Out
 
Join Date: Mar 2009
God I hope it fixes the issue with Microsoft Silverlight on Netflix where it stops streaming in HD (I doubt it) and also Apple TV needs a update where it fixes Netflix from snapping back to SD.
TsMkLg068426 is offline   1 Reply With Quote
Old Feb 25, 2014, 12:14 PM   #15
hammie14
macrumors member
 
Join Date: Mar 2010
Location: London, UK
769mb for a late 2013 rMBP

460mb (or there a bouts) for a 2012 MBA

Wonder why the huge difference in size?
__________________
15" Late 2013 rMBP, 2.6Ghz, 16GB RAM, 1TB SSD
hammie14 is offline   0 Reply With Quote
Old Feb 25, 2014, 12:14 PM   #16
milo
macrumors 603
 
Join Date: Sep 2003
What build number?
milo is offline   0 Reply With Quote
Old Feb 25, 2014, 12:15 PM   #17
leventozler
macrumors member
 
Join Date: Feb 2009
Combo link?
leventozler is offline   0 Reply With Quote
Old Feb 25, 2014, 12:15 PM   #18
MattMJB0188
macrumors 65816
 
MattMJB0188's Avatar
 
Join Date: Dec 2009
Location: Indiana
I didn't think anyone was actually using Mavericks?
MattMJB0188 is offline   5 Reply With Quote
Old Feb 25, 2014, 12:16 PM   #19
proline
macrumors 6502
 
Join Date: Nov 2012
Quote:
Originally Posted by musika View Post
Good. Should have been out four days ago.
Hatters gotta hate. Heaven forfend Apple spend four whole days to make sure they get it right.
proline is offline   44 Reply With Quote
Old Feb 25, 2014, 12:16 PM   #20
tywebb13
macrumors 6502a
 
Join Date: Apr 2012
Build number is 13C64
tywebb13 is offline   3 Reply With Quote
Old Feb 25, 2014, 12:16 PM   #21
iSee
macrumors 68030
 
iSee's Avatar
 
Join Date: Oct 2004
Quote:
Originally Posted by musika View Post
Good. Should have been out four days ago.
you should goto fail;
__________________
"Nobody ever reads these things so I can write anything. I'd eat bananas every day if they were crunchy."
iSee is offline   50 Reply With Quote
Old Feb 25, 2014, 12:16 PM   #22
petvas
macrumors 68040
 
petvas's Avatar
 
Join Date: Jul 2006
Location: Mannheim, Germany
Send a message via AIM to petvas Send a message via MSN to petvas
With this release Mavericks achieves a good maturity level. The last weeks with 10.9.2 were much better than with the previous versions, especial Mail.app has become much better.
__________________
iMac 27" (Late 2013 - 3,2Ghz i5 CPU, 32GB RAM, 512GB SSD); Retina Macbook Pro 13" Mid 2013, 8GB RAM, 256GB SSD; iPad Air Cellular 64GB white/silver; iPhone 5S 32GB Grey;
petvas is offline   0 Reply With Quote
Old Feb 25, 2014, 12:17 PM   #23
C DM
macrumors G3
 
Join Date: Oct 2011
Quote:
Originally Posted by sebastiann01 View Post
whoever said they usually come out around 1pm was spot on
Pretty much anyone/everyone given that that is the usual time updates get released (it's not always the case, but more often than not).
C DM is offline   0 Reply With Quote
Old Feb 25, 2014, 12:20 PM   #24
Luap
macrumors 6502a
 
Luap's Avatar
 
Join Date: Jul 2004
Finally! Now we can wait for 10.9.3!
Woooo!!
Luap is offline   25 Reply With Quote
Old Feb 25, 2014, 12:21 PM   #25
milo
macrumors 603
 
Join Date: Sep 2003
Hopefully we'll see a download link soon, doesn't show up on apple's main download page yet.
milo is offline   0 Reply With Quote

Reply
MacRumors Forums > News and Article Discussion > MacRumors.com News Discussion

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Similar Threads
thread Thread Starter Forum Replies Last Post
Apple Releases iOS 7.0.6 With Fix for SSL Connection Verification MacRumors MacRumors.com News Discussion 276 Mar 7, 2014 12:24 PM
Apple Releases Major Final Cut Pro X Update with Dual Viewers, Multichannel Audio Tools, RED Camera Support and More MacRumors MacRumors.com News Discussion 177 Jan 16, 2014 07:18 AM
Apple Releases iOS 7.0.4 With Fix for FaceTime Call Issue MacRumors MacRumors.com News Discussion 334 Dec 3, 2013 12:17 AM
Apple Releases Java Update to Fix New Zero-Day Vulnerability MacRumors Mac Blog Discussion 21 Mar 5, 2013 04:36 PM

Forum Jump

All times are GMT -5. The time now is 11:28 PM.

Mac Rumors | Mac | iPhone | iPhone Game Reviews | iPhone Apps

Mobile Version | Fixed | Fluid | Fluid HD
Copyright 2002-2013, MacRumors.com, LLC