|
|
| Welcome to the Mac Forums forums. Please read the FAQ if you have questions. Register to participate. |
|
|||||||
| TouchArcade.com - iPhone Game Reviews and News |
|
|
Thread Tools | Search this Thread | Display Modes |
|
|
#1 |
|
macrumors 68030
Join Date: Jan 2002
Location: Ha ha haaa!
|
Apple Releases Security Update 2004-09-07
In your software update:
Security Update 2004-09-07 delivers a number of security enhancements and is recommended for all Macintosh users. This update includes the following components: CoreFoundation IPSec Kerberos libpcap lukemftpd NetworkConfig OpenLDAP OpenSSH PPPDialer rsync Safari tcpdump For detailed information on this Update, please visit this website: http://www.info.apple.com/kbnum/n61798 |
|
|
|
|
#2 |
|
macrumors 68020
Join Date: Aug 2003
Location: l'Allemagne
|
Safari? What should be wrong with safari? The version and build is the same...
__________________
No Mac no fun...
|
|
|
|
|
#3 |
|
macrumors member
Join Date: Aug 2004
Location: UK
|
No Probs
Just installed on iMac G3 - no meltdown so far!
Damn - I wish I just installed Win SP 2 so I would have something to moan about. Guess I'll have to suffer an easy life.
|
|
|
|
|
#4 | |
|
macrumors 65816
Join Date: Oct 2003
Location: Vancouver
|
Quote:
|
|
|
|
|
|
#5 |
|
macrumors newbie
Join Date: Oct 2003
|
just becasue they update libraries belonging to the application doesn't mean they have to increment the version number
here is the complete list of changes: Component: Apache 2 CVE-IDs: CAN-2004-0493, CAN-2004-0488 Available for: Mac OS X Server 10.2.8, Mac OS X Server 10.3.4, Mac OS X Server 10.3.5 Impact: Exposure to a potential Denial of Service. Description: The Apache Organization has released Apache version 2.0.50. This release fixes a number of denial of service vulnerabilities. We have updated Apache to version 2.0.50 which only ships with Mac OS X Server, and is off by default. Component: CoreFoundation CVE-ID: CAN-2004-0821 Available for: Mac OS X 10.2.8, Mac OS X 10.3.4, Mac OS X 10.3.5, Mac OS X Server 10.2.8, Mac OS X Server 10.3.4, Mac OS X Server 10.3.5 Impact: Privileged programs using CoreFoundation can be made to load a user supplied library. Description: Bundles using the CoreFoundation CFPlugIn facilities can include directions to automatically load plugin executables. With a specially crafted bundle this could also occur for privileged programs, permitting a local privilege escalation. CoreFoundation now prevents automatic executable loading for bundles that already have a loaded executable. Credit to Kikuchi Masashi <kik@ms.u-tokyo.ac.jp> for reporting this issue. Component: CoreFoundation CVE-ID: CAN-2004-0822 Available for: Mac OS X 10.2.8, Mac OS X 10.3.4, Mac OS X 10.3.5, Mac OS X Server 10.2.8, Mac OS X Server 10.3.4, Mac OS X Server 10.3.5 Impact: An environment variable can be manipulated to cause a buffer overflow which can result in a privilege escalation Description: By manipulating local environment variables a program could potentially be leveraged by a local attacker to execute arbitrary code. This can only be exploited with access to a local account. Validity checks for local environment variables are now provided. Credit to <aaron@vtty.com> for reporting this issue. Component: IPSec CVE-ID: CAN-2004-0607 Available for: Mac OS X 10.2.8, Mac OS X 10.3.4, Mac OS X 10.3.5, Mac OS X Server 10.2.8, Mac OS X Server 10.3.4, Mac OS X Server 10.3.5 Impact: When using certificates, unauthenticated hosts may be able to negotiate an IPSec connection. Description: When configured to use X.509 certificates to authenticate remote hosts, a certificate verification failure does not abort the key exchange. Mac OS X does not use certificates for IPSec by default so this issue only affects configurations that have been manually configured. IPSec now verifies and aborts a key exchange if a certificate verification failure occurs. Component: Kerberos CVE-ID: CAN-2004-0523 Available for: Mac OS X 10.2.8, Mac OS X 10.3.4, Mac OS X 10.3.5, Mac OS X Server 10.2.8, Mac OS X Server 10.3.4, Mac OS X Server 10.3.5 Impact: Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier could permit remote attackers to execute arbitrary code. Description: The buffer overflow can only be exploited if "auth_to_local_names" or "auth_to_local" support is also configured in the edu.mit.Kerberos file. Apple does not enable this by default. The security fix was back ported and applied to the Mac OS X versions of Kerberos. The Mac OS X and Mac OS X Server version of Kerberos is not susceptible to the recent "double-free" issue reported in the CERT vulnerability note VU#350792 (CAN-2004-0772). Credit to the MIT Kerberos Development Team for informing us of this issue. Component: lukemftpd CVE-ID: CAN-2004-0794 Available for: Mac OS X 10.2.8, Mac OS X 10.3.4, Mac OS X 10.3.5, Mac OS X Server 10.2.8, Mac OS X Server 10.3.4, Mac OS X Server 10.3.5 Impact: A race condition that can permit an authenticated remote attacker to cause a denial of service or execute arbitrary code Description: If the FTP service has been enabled, and a remote attacker can correctly authenticate, then a race condition would permit them to stop the FTP service or execute arbitary code. The fix is to replace the lukemftpd FTP service with tnftpd. lukemftp is installed but not activated in Mac OS X Server, which instead uses xftp. Credit to Luke Mewburn of the NetBSD Foundation for informing us of this issue. Component: OpenLDAP CVE-ID: CAN-2004-0823 Available for: Mac OS X 10.3.4, Mac OS X 10.3.5, Mac OS X Server 10.3.4, Mac OS X Server 10.3.5 Impact: A crypt password can be used as if it were a plain text password. Description: Backwards compatibility with older LDAP implementations permits the storing of a crypt password in the userPassword attribute. Some authentication validation schemes can use this value as if it were a plain text password. The fix removes the ambiguity and always uses this type of field as a crypt password. This issue does not occur in Mac OS X 10.2.8. Credit to Steve Revilak of Kayak Software Corporation for reporting this issue. Component: OpenSSH CVE-ID: CAN-2004-0175 Available for: Mac OS X 10.2.8, Mac OS X 10.3.4, Mac OS X 10.3.5, Mac OS X Server 10.2.8, Mac OS X Server 10.3.4, Mac OS X Server 10.3.5 Impact: A malicious ssh/scp server can overwrite local files Description: A directory traversal vulnerability in the scp program permits a malicious remote server to overwrite local files. The security fix was backported and applied to the Mac OS X versions of OpenSSH. Component: PPPDialer CVE-ID: CAN-2004-0824 Available for: Mac OS X 10.2.8, Mac OS X 10.3.4, Mac OS X 10.3.5, Mac OS X Server 10.2.8, Mac OS X Server 10.3.4, Mac OS X Server 10.3.5 Impact: A malicious user can overwrite system files resulting in a local privilege escalation Description: PPP components performed insecure accesses of a file stored in a world-writeable location. The fix moves the log files to a non-world-writeable location. Component: QuickTime Streaming Server Available for: Mac OS X Server 10.2.8, Mac OS X Server 10.3.4, Mac OS X Server 10.3.5 CVE-ID: CAN-2004-0825 Impact: A denial of service requiring a restart of the QuickTime Streaming Server Description: A particular sequence of client operations can cause a deadlock on the QuickTime Streaming Server. The fix updates the code to eliminate this deadlock condition. Component: rsync CVE-ID: CAN-2004-0426 Available for: Mac OS X 10.2.8, Mac OS X 10.3.4, Mac OS X 10.3.5, Mac OS X Server 10.2.8, Mac OS X Server 10.3.4, Mac OS X Server 10.3.5 Impact: When rsync is run in daemon mode a remote attacker can write outside of the module path unless the chroot option has been set. Description: rsync before version 2.6.1 does not properly sanitize paths when running a read/write daemon with the chroot option turned off. The fix updates rsync to version 2.6.2. Component: Safari CVE-ID: CAN-2004-0361 Available for: Mac OS X 10.2.8, Mac OS X Server 10.2.8 Impact: A JavaScript array of negative size can cause Safari to access out of bounds memory resulting in an application crash. Description: Storing objects into a JavaScript array allocated with negative size can overwrite memory. Safari now stops processing JavaScript programs if an array allocation fails. This security enhancement was previously made available in Safari 1.0.3, and is being applied inside the Mac OS X 10.2.8 operating system as an extra layer of protection for customers who have not installed that version of Safari. This is a specific fix for Mac OS X 10.2.8 and the issue does not exist in Mac OS X 10.3 or later systems. Component: Safari CVE-ID: CAN-2004-0720 Available for: Mac OS X 10.2.8, Mac OS X 10.3.4, Mac OS X 10.3.5, Mac OS X Server 10.2.8, Mac OS X Server 10.3.4, Mac OS X Server 10.3.5 Impact: An untrusted web site can inject content into a frame intended to be used by another domain. Description: A web site that uses multiple frames can have some of its frames replaced with content from a malicious site if the malicious site is visited first. The fix imposes a set of parent/child rules preventing the attack. Component: SquirrelMail CVE-ID: CAN-2004-0521 Available for: Mac OS X 10.2.8, Mac OS X 10.3.4, Mac OS X 10.3.5, Mac OS X Server 10.2.8, Mac OS X Server 10.3.4, Mac OS X Server 10.3.5 Impact: SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements Description: SquirrelMail before 1.4.3 RC1 is vulnerable to SQL injection which permits unauthorized SQL statements to be run. The fix updates SquirrelMail to version 1.4.3a Component: tcpdump CVE-IDs: CAN-2004-0183, CAN-2004-0184 Available for: Mac OS X 10.2.8, Mac OS X 10.3.4, Mac OS X 10.3.5, Mac OS X Server 10.2.8, Mac OS X Server 10.3.4, Mac OS X Server 10.3.5 Impact: Maliciously crafted packets can cause a crash of a running tcpdump Description: The detailed printing functions for ISAKMP packets do not perform correct bounds checking and cause an out-of-bounds read which results in a crash. The fix updates tcpdump to version 3.8.3. Last edited by Gordon Werner : Sep 7, 2004 at 05:37 PM. |
|
|
|
|
#6 | |
|
macrumors newbie
Join Date: Mar 2003
|
Quote:
|
|
|
|
|
|
#7 |
|
macrumors regular
Join Date: Oct 2003
|
DO you get the feeling we are not about to have to start worrying about viruses?
![]() I've just put my crappy XP machine on the internet, and already, just a day later, i'm being bugged by this; http://www.doxdesk.com/parasite/LinkReplacer.html It's a right pain in the ass, but at least the pop-ups start with something that makes sense.... "Microsoft Warning!" fair point. I CANNOT wait until my G5 iMac arrives and I can thow this noisy piece-o-s**t away.
__________________
no use for a signature |
|
|
|
|
#8 |
|
Demi-God (Moderator)
Join Date: Oct 2001
Location: San Diego, CA
|
Had an odd hang when it went to restart, but I did an fsck and permissions repair afterwards and all seems to be fine.
__________________
Join MacRumors.com - Team Folding! |
|
|
|
|
#9 |
|
macrumors regular
Join Date: Nov 2003
|
Kudos to Apple for the detail they provide about the fixes (they even mention who alerted them -- how cool is that?). This openness should go a long way towards correcting Apple's reputation for secrecy regarding security.
|
|
|
|
|
#10 |
|
macrumors member
Join Date: Dec 2003
Location: New Zealand
|
Security Update number ??
It is me or does it seem that there are more security updates than ever from Apple??
A couple of years ago security updates were infrequently, but now it seems that they a coming every couple of months - does this indicate slippage in quality control???
|
|
|
| fatbarstard |
| View Public Profile |
| Find More Posts by fatbarstard |
|
|
#11 | |
|
macrumors 601
Join Date: Jun 2003
Location: Burnsville, Minnesota, USA
|
Quote:
If you don't know how to drive a car get off the road. If you don't know how to operate Windows safely get off the platform. And if you are forced to either drive a car or use Windows then LEARN how to use it safely. Easy no?No one who is interested in a secure environment takes Internet Exploder seriously. That was your first mistake. Second. Do you have a firewall? No? Second mistake. Third. Windows Update? Never did it? Game over man! Game over!!
__________________
-iPod Video 160GB
-MacBook Pro Core 2 Duo 2.33Ghz/3GB RAM/250GB -Newton 4700 (a.k.a iPaq 4700) -Dell 2405FPW 24" Widescreen Last edited by SiliconAddict : Sep 7, 2004 at 06:04 PM. |
|
|
|
| SiliconAddict |
| View Public Profile |
| Find More Posts by SiliconAddict |
|
|
#12 |
|
macrumors 6502a
|
I don't notice a thing different.
__________________
60GB iPod | 17" Mac Book Pro | Mac OS 10.5.4 | 8GB iphone |
|
|
| robotrenegade |
| View Public Profile |
| Find More Posts by robotrenegade |
|
|
#13 | |
|
macrumors 601
Join Date: Jun 2003
Location: Burnsville, Minnesota, USA
|
Quote:
No OS is going to be flawless and that sure as heck includes OS X or OS XI or OS XII. or OS pi.
__________________
-iPod Video 160GB
-MacBook Pro Core 2 Duo 2.33Ghz/3GB RAM/250GB -Newton 4700 (a.k.a iPaq 4700) -Dell 2405FPW 24" Widescreen |
|
|
|
| SiliconAddict |
| View Public Profile |
| Find More Posts by SiliconAddict |
|
|
#14 |
|
macrumors 6502a
Join Date: Sep 2003
Location: The Utah Alps
|
I have a theory - can anyone back me up on it. Apple releases a new major OS update which is quick because it doesn't have to patch all this stuff. People find security holes and now all the patches get in the way and slow things down. It just seems like each time I install one of these patches things to slow down a bit. Any experience from anyone?
__________________
Always looking for a faster Mac. |
|
|
|
|
#15 | ||
|
macrumors 65816
Join Date: Jun 2004
|
Quote:
http://docs.info.apple.com/article.html?artnum=61798 http://docs.info.apple.com/article.html?artnum=25631 Quote:
__________________
Steve Balmers the CEO of Microsoft... Dance Monkey, Developers!, The remix, The ad |
||
|
|
|
|
#16 |
|
macrumors 68000
Join Date: Jan 2004
Location: Cape Cod
|
You shouldn't notice any slowdown if you take the proper procedures. (although I've never experienced any slow down of any kind when installing an Apple update, rather an increase in speed)
Repair Permissions periodic daily/weekly/monthly fsck update prebindings pray to god that your computer does not melt down.
__________________
For SCIENCE!! |
|
|
| musicpyrite |
| View Public Profile |
| Find More Posts by musicpyrite |
|
|
#17 | |
|
macrumors 68000
Join Date: Jan 2004
|
Quote:
|
|
|
|
|
|
#18 | |
|
macrumors member
Join Date: Jun 2003
|
Quote:
hey dude, if you're gonna throw it away, i'll pay for shipping/pick up and get it from you. I wouldn't mind another websurfing machine
|
|
|
|
|
|
#19 | |
|
macrumors 601
|
Quote:
1. It's not Microsoft's fault if an XP user uses Internet Explorer and bad things happen; 2. You must learn to fully and properly use the software before using a computer (this would prohibit 99% of people from using them) 3. The user, not the software manufacturer, is responsible for making the software secure enough to use in real-life applications... Need I go on? Seriously, it's one thing to blindly say "PCs suck Macs rule end of debate", but everything he mentioned were valid points that many, many users deal with. PC users, not Mac users. I've never had a page hijack my browser simply because I dared use the software that came installed having a bad day are we? paul |
|
|
|
| rainman::|:| |
| View Public Profile |
| Find More Posts by rainman::|:| |
|
|
#20 |
|
macrumors 68040
Join Date: Aug 2003
Location: Manila - Nottingham - Philadelphia - Santa Barbara - Boston (ugh hate not knowing where to call home)
|
just installed. i havent had any sercurity issues in the past but i suppose its better not to tempt fate
__________________
17" MBP , 2 gig ram, 200 gig fw800 + 120 gig fw400 + 250 gig usb2 ext, 5g 80gig Ipod, Tiger ![]() d200 & d70 |
|
|
|
|
#21 | |
|
macrumors 68000
Join Date: Jan 2004
Location: Cape Cod
|
Quote:
I just know it's good for your computer if you do it a couple of times every month. Google it if you want more info. EDIT: i forgot how to use them. open up the terminal, type fsck, fsck will do it's thing then when your done type 'sudo update_prebinding -root -force /' and that will update your prebindings. to repair permissions in the terminal type 'diskutil repairpermissions /'.
__________________
For SCIENCE!! |
|
|
|
| musicpyrite |
| View Public Profile |
| Find More Posts by musicpyrite |
|
|
#22 | |
|
macrumors regular
Join Date: Oct 2003
|
Quote:
I may have to switch back to XP for a while but i'm not suicidal! Firefox all the way. ![]() As to the updates.. i wish I could've gotten that far. It says there's 18 or so updates, but it completely died while trying to install them. I don't think it'll ever get to SP2 at this rate. And have installed about 5 virus checkers which all tell me that I have x and y viruses but than ask for $z to remove them.
__________________
no use for a signature |
|
|
|
|
|
#23 | |
|
macrumors 6502a
Join Date: Oct 2003
Location: Somewhere in the USA
|
Quote:
prebindings: Look here and scroll down to the "Update the prebinding" section. pray to god that your computer does not melt down: This site might help.
|
|
|
|
|
|
#24 |
|
macrumors 65816
Join Date: Jan 2004
|
Installed update.
Restarted. Repaired permissions. Opened Safari. Tried to reply to this thread. Kernel Panic! Stupid security update.
__________________
i love brits |
|
|
| keysersoze |
| View Public Profile |
| Find More Posts by keysersoze |
|
|
#25 | |
|
macrumors regular
|
Quote:
__________________
Mac mini 1.42MHz, 512 MB RAM Bluetooth, Airport Extreme, OS 10.4.1 iPod mini 6 GB Sold: iMac DV SE 400 MHz, 6100/60, 5300c, Mac SE, original iPod, Bronze PowerBook. Dull Latitude 810 2.0 GHz WUXGA. The screen kicks a**! Selling: HP PeeCee 2.4GHz |
|
|
|
| Thread Tools | Search this Thread |
| Display Modes | |
|
|