toggle

AAPL Stock: 442.93 ( 0 )

http://www.macnn.com/articles/03/02/14/mac.os/

Mac OS X 10.2.4 security highlights

updated 06:05 pm EST, Fri February 14, 2003

 
", 0, 0);


Apple notes that , which addresses a general security concern.

Details:


  • Sendmail: Fixes CAN-2002-0906 Buffer overflow in Sendmail before 8.12.5, when
    configured to use a custom DNS map to query TXT records, could permit a denial
    of service attack and possibly allow execution of arbitrary code. Mac OS X
    10.2.4 contains Sendmail 8.12.6 with the SMRSH fix applied to also address
    CAN-2002-1165 .


  • AFP: Fixes CAN-2003-0049 "AFP login permissions for the system
    administrator". Provides an option whereby a system administrator may or may
    not be allowed to log in as a user, authenticating via their admin password.
    Previously, administrators could always log in as a user, authenticating via
    their own admin password.


  • Classic: Fixes CAN-2003-0088 , where an attacker may change an environment
    variable to create arbitrary files or overwrite existing files, which could lead
    to obtaining elevated privileges. (Apple credits Dave G. from @stake, Inc. for
    discovering this issue.)


  • Samba: Previous releases of Mac OS X are not vulnerable to CAN-2002-1318 , an
    issue in Samba's length checking for encrypted password changes. Mac OS X
    currently uses Directory Services for authentication, and does not call the
    vulnerable Samba function. However, to prevent a potential future exploit via
    this function, the patch from Samba 2.2.7 was applied although the version of
    Samba was not changed for this update release.

  • by MacNN Staff

    Post tools:

    TAGS :

     troubleshooting
     
    close
    Photo
    toggle

    Network Headlines

    toggle

    Most Popular

    MacNN Sponsor

    Recent Reviews

    MaxUpgrades MaxConnect for 2006-2008 Mac Pro

    Nobody outside of Cupertino's privileged bunch knows the future of the Mac Pro line for sure. Despite Apple's reluctance to tell us wh ...

    Brother HL-3170CDW LED Printer

    We've mentioned before that we are far from a paperless society. For now, at least, there are tasks that require a piece of paper for ...

    HTC One

    It is hard to overstate just how critically important the HTC One is to the Taiwanese company’s fortunes. Despite its alarming decline ...

    toggle

    Most Commented