toggle

AAPL Stock: 561.28 ( + 30.9 )

Apple releases Security, MPEG-2 playback updates

updated 01:25 am EST, Sat December 20, 2003

Security Update released


Apple has released Security Update 2003-12-19, which it says delivers a number of security enhancements, including several updated components: AFP Server, ASN.1 Decoding for PKI, cd9660.util, Directory Services, fetchmail, fs_usage, rsync, and System Initialization. The update was via a download at the Apple Store). Both are available via the Mac OS X Software Update.


  • AppleFileServer: Fixes CAN-2003-1007 to improve the handling of malformed requests.



  • cd9660.util: Fixes CAN-2003-1006, a buffer overflow vulnerability in
    the filesystem utility cd9660.util.
    Credit to KF of Secure Network Operations for reporting this issue.



  • Directory Services: Fixes CAN-2003-1009. The default settings are
    changed to prevent an inadvertent connection in the event of a
    malicious DHCP server on the computer's local subnet. Further
    information is provided in Apple's Knowledge Base article:

    Credit to William A. Carrel for reporting this issue.



  • fetchmail: Fixes CAN-2003-0792. Updates are provided to fetchmail that
    improve its stability when receiving malformed messages.



  • fs_usage: Fixes CAN-2003-1010. The fs_usage tool has been improved to
    prevent a local privilege escalation vulnerability. This tool is
    used to collect system performance information and requires admin
    privileges to run.
    Credit to Dave G. of @stake for reporting this issue.



  • rsync: Fixes CAN-2003-0962 by improving the security of the rsync
    server.



  • System initialization: Fixes CAN-2003-1011. The system initialization
    process has been improved to restrict root access on a system that
    uses a USB keyboard.



Note: The following fixes which appear in "Security Update 2003-12-19 for Panther" are not included in "Security Update 2003-12-19 for Jaguar" since the Jaguar versions of Mac OS X and Mac OS X Server are not vulnerable to these issues:

  • CAN-2003-1005: ASN.1 Decoding for PKI
  • CAN-2003-1008: Screen Saver text clippings


by MacNN Staff

toggle

Comments

  1. MacNN.com Reader

    Fresh-Faced Recruit

    Joined: Jul 2001

    0

    um?

    Couldn't they have just included the security update with 10.3.2? That makes 5 downloads in the last two days (groan).

  1. MacNN.com Reader

    Fresh-Faced Recruit

    Joined: Jul 2001

    0

    Nah

    13 updates total actually in the last 5 days. Java 3D, OS X, ARD, Security, FCP, LiveType, DVD Studio, QT 6.5, QT MPEG Fix, iTunes, G5 Firmware, Battery, and Xcode.

    Anyways, it looks as if the Security update and the OS X update were on different tracks (it includes the cd exploit fix that was publicized dec 13th). So in order to test the things properly they had to be release separately.

  1. MacNN.com Reader

    Fresh-Faced Recruit

    Joined: Jul 2001

    0

    Hmm

    I can honestly say I have rebooted my Mac more than my PC!

  1. MacNN.com Reader

    Fresh-Faced Recruit

    Joined: Jul 2001

    0

    So what.

    The total amount of updates/patches apply for only a (small) part of users. Only few have to install them all. And those who do are power users and have usually fast connections. Big deal.

  1. MacNN.com Reader

    Fresh-Faced Recruit

    Joined: Jul 2001

    0

    Old hardware

    I thought I'd go and download this only to find you need a 500MHz G4 or faster - ho-hum time to upgrade?????

  1. MacNN.com Reader

    Fresh-Faced Recruit

    Joined: Jul 2001

    0

    10.3.2 is buggy...

    ...and flashing my upper right menus on & off - kind of scary now that everything is cryptic in UNIX land - oh well another weekend struggling with my mac...
    ;-)

  1. MacNN.com Reader

    Fresh-Faced Recruit

    Joined: Jul 2001

    0

    10.3.2 perfect here...

    What the heck do you have installed on your system?

  1. MacNN.com Reader

    Fresh-Faced Recruit

    Joined: Jul 2001

    0

    re: old hardware

    What are you talking about? What requires a 500mhz G4? I just applied the updates on my 400mhz G3 and never got a message telling me a faster CPU was needed.

  1. MacNN.com Reader

    Fresh-Faced Recruit

    Joined: Jul 2001

    0

    500 MHz G4...

    re

  1. MacNN.com Reader

    Fresh-Faced Recruit

    Joined: Jul 2001

    0

    500 MHz G4...(2nd time)

    [Must learn to type more carefully...]

    Sorry did not make myslef clear, a 500MHz G4 is needed for the QT MPEG-2 player according to this:-

    http://www.apple.com/quicktime/products/mpeg2playback/system_req.html

    However, if you have used this on a 400 MHz G3 successfully please let me know

Login Here

Not a member of the MacNN forums? Register now for free.

 
close
Photo
toggle

Network Headlines

toggle

Most Popular

MacNN Sponsor

Recent Reviews

iHome iW2 AirPlay speaker

iHome generally isn't known as a luxury brand when it comes to audio, but it is prolific -- the company's docks and speakers are every ...

Logitech Ultrathin Keyboard Cover

One of the iPad's main weaknesses has always been productivity. It's not a question of apps; while it has taken a little time for a na ...

Logitech UE Air Speaker

If maybe a little more slowly than Apple would like, AirPlay is becoming a staple of the wireless speaker market for iOS devices. The ...

toggle

Most Commented