Register FAQ/Rules Forum Spy Search Today's Posts Mark Forums Read

Welcome to the Mac Forums forums. Please read the FAQ if you have questions. Register to participate.

 
Go Back   Mac Forums > News and Article Discussion > MacRumors.com News Discussion
TouchArcade.com - iPhone Game Reviews and News

Reply
 
Thread Tools Search this Thread Display Modes
Old Feb 15, 2007, 07:06 PM   #1
MacRumors
macrumors bot
 
Join Date: Apr 2001
Apple Security Update 2007-002, Daylight Savings Update and More



Apple released a number of software updates today under Mac OS X's Software Update feature. The first is a security update that "is recommended for all users and improves the security of the following components:"

- CoreServices
- iChat
- UserNotificationCenter

More detailed information about the changes are listed at Apple.

Apple also revealed a Daylight Saving Time Update due to recent changes on the dates Daylight Savings will occur this year:

Quote:
The Daylight Saving Time Update for Mac OS X and Mac OS X Server addresses recent changes in the way Daylight Saving Time will be observed in the U.S. and Canada beginning in March 2007 and includes the latest time zone information for the rest of the world.
More information is at http://docs.info.apple.com/article.html?artnum=305056

Other updates also listed by Apple include:

- Java for Mac OS X 10.3 Update 5
- Java for Mac OS X 10.4 Update 5
- WebObjects 5.3.3
- Final Cut Pro 5.1.3
MacRumors is offline   Reply With Quote
Old Feb 15, 2007, 07:08 PM   #2
bloogersnigen
macrumors regular
 
Join Date: May 2005
Location: Wherever the water flows
downloaded all, works fine. Haven't noticed anything different yet. Wait why is the screen flickering!
__________________
On a river near you since 1991
bloogersnigen is offline   Reply With Quote
Old Feb 15, 2007, 07:17 PM   #3
ksgant
macrumors regular
 
Join Date: Jan 2006
Location: Chicago
I JUST got my 24" iMac yesterday, and thought my software updates were going to be done for a while, then I noticed this popping up.

Worked perfectly though, so no complaints.
ksgant is offline   Reply With Quote
Old Feb 15, 2007, 07:22 PM   #4
rye9
macrumors 65816
 
rye9's Avatar
 
Join Date: Sep 2005
Location: New York (not NYC)
isn't an OS update due soon though which will include the security update?
__________________
-12" iBook G4 (1.33 G4, 40 GB, 1GB, Mac OS 10.4.11)
-NEW 13" MBP
-iPod mini 2G + iPod nano 3G
-iPhone 3G

=
rye9 is offline   Reply With Quote
Old Feb 15, 2007, 07:25 PM   #5
thejadedmonkey
macrumors 68040
 
thejadedmonkey's Avatar
 
Join Date: May 2005
Location: Pa
Send a message via AIM to thejadedmonkey
iChat update?
__________________
Mac Mini G4 • MacBook Pro • iPod Nano
"Good judgement comes from experience,
experience comes from bad judgement.
- Mark Twain
thejadedmonkey is offline   Reply With Quote
Old Feb 15, 2007, 07:27 PM   #6
gerrycurl
macrumors newbie
 
Join Date: Jun 2004
nvidia 7300 firmware for mac pro

here's the link from apple, as usual no information:

http://www.apple.com/downloads/macos...areupdate.html

i was hoping this firmware update would allow me to now get the drivers to have portrait view on my samsung 24" synchmaster, but it gives me nothing.

what the heck is this firmware for? performance enhancements?

and how come nvidia has no apple drivers or software?

i'm freaking frustrated with nvidia, this will only force me to go with ati, or buy a completely new rig and install windows vista... all i want is portrait view!

by the way, i installed all the other updates, things are working smoothly...
gerrycurl is offline   Reply With Quote
Old Feb 15, 2007, 07:28 PM   #7
Doctor Q
macrumors god
 
Doctor Q's Avatar
 
Join Date: Sep 2002
Location: Los Angeles, Row Q Seat 1
Security Update 2007-002 details

Finder

Mounting a maliciously-crafted disk image may lead to an application crash or arbitrary code execution
A buffer overflow exists in Finder's handling of volume names. By enticing a user to mount a malicious disk image, an attacker could trigger this issue, which may lead to an application crash or arbitrary code execution. A proof of concept for this issue has been published on the "Month of Apple Bugs" website (MOAB-09-01-2007). This update addresses the issue by performing additional validation of disk images. This issue does not affect systems prior to Mac OS X v10.4. Credit to Kevin Finisterre of DigitalMunition for reporting this issue.
iChat

Attackers on the local network may be able to cause iChat to crash
A null pointer dereference in iChat's Bonjour message handling could allow a local network attacker to cause an application crash. A proof of concept for this issue in Mac OS X v10.4 has been published on the "Month of Apple Bugs" website (MOAB-29-01-2007). A similar issue exists in Mac OS X v10.3. This update addresses the issues by performing additional validation of Bonjour messages.
iChat

Visiting malicious websites may lead to an application crash or arbitrary code execution
A format string vulnerability exists in the iChat AIM URL handler. By enticing a user to access a maliciously-crafted AIM URL, an attacker can trigger the overflow, which may lead to an application crash or arbitrary code execution. A proof of concept for this issue has been published on the "Month of Apple Bugs" website (MOAB-20-01-2007). This update addresses the issue by performing additional validation of AIM URLs.
UserNotification

Malicious local users may be able to obtain system privileges
The UserNotificationCenter process runs with elevated privileges in the context of a local user. This may allow a malicious local user to overwrite or modify system files. A program that triggers this issue has been published on the "Month of Apple Bugs" website (MOAB-22-01-2007). This update addresses the issue by having UserNotificationCenter drop its group privileges immediately after launching.
__________________
Oh do pay attention 007. In the wrong hands, this Dual 2.93GHz Quad-Core Nehalem Mac Pro could be very dangerous.
Doctor Q is offline   Reply With Quote
Old Feb 15, 2007, 07:32 PM   #8
lazyrighteye
macrumors 6502a
 
lazyrighteye's Avatar
 
Join Date: Jan 2002
Location: Denver, CO
Downloaded & Installed

No issues, yet.

10.4.8
Dual 2 GHz PPC G5
2.5 GB DDR2 SDRAM
lazyrighteye is offline   Reply With Quote
Old Feb 15, 2007, 07:36 PM   #9
apfhex
macrumors 68030
 
apfhex's Avatar
 
Join Date: Aug 2006
Location: Northern California
Interesting all MOAB fixes. Like to see MS respond to a Month of Vista Bugs.

I thought the DST issue had been addressed long ago, or have there been even more recent changes to DST? Ah I see, they're addressing more regions, as well as 10.3 users.

Quote:
The 2007 time zone and Daylight Saving Time rule changes for the United States and most of Canada are already available in Mac OS X 10.4.5 or later.

Some additional regions that recently adopted time zone and DST changes are available in the February, 2007 Daylight Saving Time Update.
__________________
2006 Mac Pro: 2.66Ghz, 6GB RAM, 8800GT, 23" ACD, Snow Leopard/Windows 7
iPhone 3GS 16GB Black
apfhex is offline   Reply With Quote
Old Feb 15, 2007, 07:55 PM   #10
Markabre
macrumors newbie
 
Join Date: Feb 2007
I wonder if this is due to some kind of delay with 10.4.9. It seemed just around the corner a few weeks ago with constant seeds and few known issues but then it all went quiet....
Markabre is offline   Reply With Quote
Old Feb 15, 2007, 08:03 PM   #11
MrCrowbar
macrumors 68000
 
MrCrowbar's Avatar
 
Join Date: Jan 2006
Well, it's cool to see that Apple fixes the thing addressed in the month of apple bugs so quickly.
__________________
MrCrowbar is offline   Reply With Quote
Old Feb 15, 2007, 08:04 PM   #12
Peace
macrumors Demi-God
 
Peace's Avatar
 
Join Date: Apr 2005
Location: On top of the Storm Peaks waiting for the Time-Lost Proto Drake
Quote:
Originally Posted by Markabre View Post
I wonder if this is due to some kind of delay with 10.4.9. It seemed just around the corner a few weeks ago with constant seeds and few known issues but then it all went quiet....
Apple is waiting on some important stuff before releasing 10.4.9

Hang Loose
Peace is offline   Reply With Quote
Old Feb 15, 2007, 08:13 PM   #13
jonharris200
macrumors 6502
 
Join Date: Feb 2006
Location: London, UK
iMac 20" and black MacBook*, both Intel Core 2 Duo, both running Tiger 10.4.8, both updated fine.

* Refurb, arrived today, with 2GB RAM - yay! Sorry to repeat myself from other threads, I'm just very happy about that. Many thanks
__________________
For more info, please visit the 500 thread. Alternatively, try Page 3. But whatever you do, live different.

Last edited by jonharris200 : Feb 16, 2007 at 01:36 PM. Reason: Added 'Tiger'; Changed 2MB to 2GB :)
jonharris200 is offline   Reply With Quote
Old Feb 15, 2007, 08:16 PM   #14
justflie
macrumors 6502a
 
justflie's Avatar
 
Join Date: Nov 2005
Location: Red Sox Nation
Quote:
Originally Posted by Peace View Post
Apple is waiting on some important stuff before releasing 10.4.9

Hang Loose
I wish I could know what you know!
__________________
2 x 2.66 GHz 2009 Mac Pro, 6 GB RAM, GTX 285 ; 32GB iPhone 3GS
justflie is offline   Reply With Quote
Old Feb 15, 2007, 08:20 PM   #15
Markabre
macrumors newbie
 
Join Date: Feb 2007
Quote:
Originally Posted by Peace View Post
Apple is waiting on some important stuff before releasing 10.4.9

Hang Loose
Yeah this certainly gives me that kinda feeling. Either:

- its done and they're waiting for something for it to coincide with. I would assume a release before iphone/leopard/wwdc however.
- It's already complete well in advance of when they needed it so they can now concentrate on Leopard.
- It's been delayed to add more features than initially planned

...and why the hell am i being sucked into speculating about apple..and not a particularly exciting release either. i think i caught the bug :/ help!
Markabre is offline   Reply With Quote
Old Feb 15, 2007, 08:26 PM   #16
HailToTheVictor
macrumors regular
 
Join Date: Feb 2007
MBP CD 1.83 All Good thus far
HailToTheVictor is offline   Reply With Quote
Old Feb 15, 2007, 08:29 PM   #17
Sandfleaz
macrumors regular
 
Join Date: Jan 2007
Quote:
Originally Posted by Markabre View Post
...and why the hell am i being sucked into speculating about apple..and not a particularly exciting release either. i think i caught the bug :/ help!
Quick, purchase 100 shares of Apple stock ...the only known cure!
__________________
Funniest T-Shirts & Stuff on the net http://www.cafepress.com/shirtspot
Sandfleaz is offline   Reply With Quote
Old Feb 15, 2007, 08:39 PM   #18
iJawn108
macrumors 65816
 
iJawn108's Avatar
 
Join Date: Apr 2006
hmmm the latest camino knightly isnt runing properly
__________________
Black MacBook | Core Duo 2 GHz | 2 GB Ram | 320 GB HDD | OS X Snow Leopard 10.6 - iPod Touch | 16 GB
Camino
OpenSolaris
iJawn108 is offline   Reply With Quote
Old Feb 15, 2007, 08:41 PM   #19
puckhead193
macrumors 601
 
puckhead193's Avatar
 
Join Date: May 2004
Location: NY
the final cut update didn't come up in software updates for me
__________________
20" iMac C2D - 2.33GHz, 3 GB ram, ATI X1600 256 MB VRAM
15" pb 1.5 GHZ Rev. C
30 gig ipod 3rd gen, 60 gig 5g ipod ~ white, silver 2GB nano, 64 gig iPod Touch
puckhead193 is offline   Reply With Quote
Old Feb 15, 2007, 08:49 PM   #20
rfaulder
macrumors newbie
 
Join Date: Feb 2007
Safari seems snappier.
rfaulder is offline   Reply With Quote
Old Feb 15, 2007, 09:01 PM   #21
Grakkle
macrumors 6502a
 
Grakkle's Avatar
 
Join Date: Oct 2006
Location: Surveying my domain and feeling my superiority
Updated. Haven't noticed any difference thus far - but I've only been using the computer for a few minutes.
__________________
"What had been once his little private pain became...everyone's diarrhoea." - Daphne Du Maurier
Grakkle is offline   Reply With Quote
Old Feb 15, 2007, 09:04 PM   #22
starwxrwx
macrumors newbie
 
Join Date: Oct 2004
yay from WA for daylight savings
starwxrwx is offline   Reply With Quote
Old Feb 15, 2007, 09:07 PM   #23
lancestraz
macrumors 6502a
 
lancestraz's Avatar
 
Join Date: Nov 2005
Location: location, location…
I kernel panicked after the updates. Had to boot from the install DVD and repair disk.

Everything seems fine now.
But still... Grrrr...
lancestraz is offline   Reply With Quote
Old Feb 15, 2007, 09:11 PM   #24
boxandrew
macrumors member
 
Join Date: Apr 2005
Location: Oklahoma, OK
Slow download

All the updates downloaded fine except the 10.4 Java Update, which my mac currently estimates will take another 10 hours. Could just be a problem my end, but why would the Security and Timezone Updates be so fast compared to this?
boxandrew is offline   Reply With Quote
Old Feb 15, 2007, 09:19 PM   #25
k2k koos
macrumors 6502
 
Join Date: Jan 2003
Location: Somewhere between yesterday and tomorrow
updates

Quote:
Originally Posted by rfaulder View Post
Safari seems snappier.
Yes, I think so too, just installed, restarted and started browsing, it is defenitely snappier.... hope there are no incompatible websites out there now...there weren't that many...
__________________
The secret to creativity is knowing how to hide your sources.
k2k koos is offline   Reply With Quote

Reply

Mac Forums > News and Article Discussion > MacRumors.com News Discussion

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 06:07 PM.

Mac News | Mac Rumors | iPhone Game Reviews | iPhone Apps

Powered by vBulletin® Version 3.6.10
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright 2002-2009, MacRumors.com, LLC