Briefly: 4D at OpenBase Conf, OS X Security flaw,...
updated 07:15 am EDT, Wed July 28, 2004
OS X Security flaw
In Brief: Product experts from 4D, Inc. will present a series of sessions on using the 4th Dimension (4D) development environment at the , an update to its CAD software that provides international market support via new localized versions as well as support for AutoCAD 2005 DXF/DWG.



Forum Regular
Joined: Aug 2001
Bah!
Gotta love that security vulnerability warning.
The problem is that "Internet Connect.app" creates the file "/tmp/ppp.log" in an insecure manner, which can be exploited via symlink attacks.
No explanation of what an 'insecure manner' is, nor any mention of what a symlink attack is (hey, a hyperlink to a glossary is all we want, you boneheads).
The vulnerability has been reported in Mac OS X 10.3.4 with "Internet Connect.app" version 1.3. Prior versions may also be affected.
Reported, but was it verified? And couldn't anyone say "Hmmm, let's check out 10.2?