Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
Apple Posts Security Update 2007-004 v1.1 and Quicktime 7.1.6



Apple has posted version 1.1 of their 2007-004 update released earlier this month.

The new update incorporates the following fixes, in addition to those provided with the first update.

AirPort
Available for: Mac OS X v10.3.9

This update corrects an issue where the AirPort connection may be lost after waking from sleep. This issue only affects Mac OS X v10.3.9 with Security Update 2007-004.

FTPServer
Available for: Mac OS X Server v10.4.9

Security Update 2007-004 applied an incorrect ftp configuration file for Mac OS X Server v10.4.9 systems. Users with ftp access, who would normally be restricted to certain directories, may be able to access directories outside the normal scope. This update addresses the issue by restoring the correct version of the ftp configuration file. This issue only affects Mac OS X Server v10.4.9 with Security Update 2007-004.

In addition, Apple posted Quicktime 7.1.6 updates:

QuickTime 7.1.6 delivers numerous bug fixes, addresses a critical security issue with QuickTime for Java and includes support for:

- Final Cut Studio 2
- Timecode and closed captioning display in QuickTime Player

This update is recommended for all QuickTime 7 users

The Quicktime update fixes the exploit discovered in the $10,000 MacBook hacking contest that was won 10 days ago.

Finally, Apple also released the Airport Extreme 2007-003 updater, which "is recommended for all Intel-based Macintosh computers and includes compatibility updates for certain third-party access points configured to use WPA™ or WPA2™ security."
 
The QuickTime one mentions that it contains a security update for QuickTime and Java. Looks like Apple have just closed that attack vector anyway. Well played :)

This one and this one, in case you were wondering.
 
It would be cool to have another competition for hacking...and again and again...just to prove that mac hacks are all patched before release...and to see how many exploits can be found...
 
There's one more: AirPort Extreme Update 2007-003 (edit: like Peace said ;))

About AirPort Extreme Update 2007-003
This update is recommended for all Intel-based Macintosh computers and includes compatibility updates for certain third-party access points configured to use WPA™ or WPA2™ security.

WPA and WPA2 are trademarks of the Wi-Fi Alliance.
[link]
 
I was waiting for this QT update because FCS2 says it needs this version to run. Does this mean that FCS2 should be shipping really soon? It is May...

P-Worm
 
Wait, SUPPORT FOR CLOSED CAPTIONING in Quicktime Player?

PLEASE PLEASE, GOD I hope this means closed-captioned video downloads coming soon to iTunes. As a hearing impaired user, iTunes video downloads are useless to me. But if they support captioning, I will buy a bunch just to support a company that actually captions the video they sell.
 
The installer wouldn't let me install v1.1 of the Security Update. I'm not sure if it is because I had already installed the original version
 
I have to admit, I was tired of reading all the negative responses by Windows fanboys about the Quicktime flaw, which they blew up into an OS X flaw. Not that I think that OS X is a mightly fortified, but it will be nice to see silence ... if that's possible. :D
 
The installer wouldn't let me install v1.1 of the Security Update. I'm not sure if it is because I had already installed the original version

It's only for 10.3.9 OR Mac OS X Server. So if you don't have either, it shouldn't install.
 
Does the closed caption thingy mean that all of us international users can finally watch a movie with subtitles, even on our iPods?

If that's true, it'll be great. It only took apple 20 years or so. :p
 
Still Waiting...

When are they going to fix the WEP security so my DS will work with it?

c'mon Apple... how hard could it be? The only way I can connect with my DS is if I turn security off, not that I'm always going online with my DS, but man, that is a hassle.

:mad:
 
This is GREAT to hear! My mom was having airport problems (exactly what was described in the update) ever since the last update. Tested the router and DSL line. Nothing. Was thinking her reconditioned aiport card might be going out. Hopefully she'll install this and things will be fine again.
 
I do notice a difference in my wifi :\

Anyways there was also an update to webobjects. :p
 
[Security Update 2007-004 v1.1 not showing up in Software Update on 10.4.9]
It's only for 10.3.9 OR Mac OS X Server. So if you don't have either, it shouldn't install.

Hm? Apple posted three versions of this update: for 10.3.9, PPC and Universal. The PPC and Universal versions are meant for 10.4.9 and I would have expected them to show up in Software Update.
The MacRumors Article also mentioned a wrong setting in the FTP setup in 10.4.9. Why wouldn't Apple want to fix that ?


EDIT: Oops, Sorry. Withdrawn, your honor... :)
I, of course, misread the article... it said 10.4.9 SERVER...
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.