Hello and welcome to our community! Is this your first visit?
Register

Results 1 to 9 of 9

Thread: New Security Update

  1. #1
    Mac Fanatic docnap's Avatar
    Join Date
    Apr 2004
    Location
    Libis, Quezon City
    Age
    49
    Posts
    581

    Default New Security Update

    Hi Guys,

    Time to fire up Software Update

    Security Update 2005-003

    AFP Server
    Available for: Mac OS X v10.3.8, Mac OS X Server v10.3.8
    CVE-ID: CAN-2005-0340
    Impact: A specially crafted packet can cause a Denial of Service against the AFP Server.
    Description: A specially crafted packet will terminate the operation of the AFP Server due to an incorrect memory reference.


    AFP Server
    Available for: Mac OS X v10.3.8, Mac OS X Server v10.3.8
    CVE-ID: CAN-2005-0715
    Impact: The contents of a Drop Box can be discovered.
    Description: Fixes the checking of file permissions for access to Drop Boxes. Credit to John M. Glenn of San Francisco for reporting this issue.


    Bluetooth Setup Assistant
    Available for: Mac OS X 10.3.8, Mac OS X Server 10.3.8
    CVE-ID: CAN-2005-0713
    Impact: Local security bypass when using a Bluetooth input device.
    Description: The Bluetooth Setup Assistant may be launched on systems without a keyboard or a preconfigured Bluetooth input device. In these cases, access to certain privileged functions has been disabled within the Bluetooth Setup Assistant.


    Core Foundation
    Available for: Mac OS X v10.3.8, Mac OS X Server v10.3.8
    CVE-ID: CAN-2005-0716
    Impact: Buffer overflow via an environment variable.
    Description: The incorrect handling of an environment variable within Core Foundation can result in a buffer overflow that may be used to execute arbitrary code. This issue has been addressed by correctly handling the environment variable. Credit to iDEFENSE and Adriano Lima of SeedSecurity.com for reporting this issue.


    Cyrus IMAP
    Available for: Mac OS X Server v10.3.8
    CVE-ID: CAN-2004-1011, CAN-2004-1012, CAN-2004-1013, CAN-2004-1015, CAN-2004-1067
    Impact: Multiple vulnerabilities in Cyrus IMAP, including remotely exploitable denial of service and buffer overflows.
    Description: Cyrus IMAP is updated to version 2.2.12, which includes fixes for buffer overflows in fetchnews, backend, proxyd, and imapd. Further information is available from http://asg.web.cmu.edu/cyrus/download/imapd/changes.html.


    Cyrus SASL
    Available for: Mac OS X v10.3.8, Mac OS X Server v10.3.8
    CVE-ID: CAN-2002-1347, CAN-2004-0884
    Impact: Multiple vulnerabilities in Cyrus SASL, including remote denial of service and possible remote code execution in applications that use this library.
    Description: Cyrus SASL is updated to address several security holes caused by improper data validation, memory allocation, and data handling.


    Folder permissions
    Available for: Mac OS X v10.3.8, Mac OS X Server v10.3.8
    CVE-ID: CAN-2005-0712
    Impact: World-writable permissions on several directories, allowing potential file race conditions or local privilege escalation.
    Description: Secure folder permissions are applied to protect the installer's receipt cache and system-level ColorSync profiles. Credit to Eric Hall of DarkArt Consulting Services, Michael Haller (info@cilly.com), and (root at addcom.de) for reporting this issue.



    Mailman
    Available for: Mac OS X Server v10.3.8
    CVE-ID: CAN-2005-0202
    Impact: Directory traversal issue in Mailman that could allow access to arbitrary files.
    Description: Mailman is a software package that provides mailing list management. This update addresses an exposure in Mailman's private archive handling that allowed remote access to arbitrary files on the system. Further information is available from http://www.gnu.org/software/mailman/security.html.



    Safari
    Available for: Mac OS X v10.3.8, Mac OS X Server v10.3.8
    CVE-ID: CAN-2005-0234
    Impact: Maliciously registered International Domain Names (IDN) can make URLs visually appear as legitimate sites.
    Description: Support for Unicode characters within domain names (International Domain Name support) can allow maliciously registered domain names to visually appear as legitimate sites. Safari has been modified so that it consults a user-customizable list of scripts that are allowed to be displayed natively. Characters based on scripts that are not in the allowed list are displayed in their Punycode equivalent. The default list of allowed scripts does not include Roman look-alike scripts. Credit to Eric Johanson (ericj@shmoo.com) for reporting this issue to us. More information is available here.

  2. # ADS
    Google Adsense

    Join Date
    Always
    Location
    Advertising world
    Age
    2010
    Posts
    Many




     

  3. #2
    hannibal's Avatar
    Join Date
    Apr 2004
    Posts
    3,383

    Default

    thanks for the heads-up.

  4. #3
    Mac Freak NoisyCricket's Avatar
    Join Date
    Aug 2004
    Location
    Makati
    Age
    37
    Posts
    1,421

    Default

    thats a lot of updates

  5. #4
    victorpanlilio
    Guest victorpanlilio's Avatar

    Default So far, so good

    Installed it on my primary iBook G4 (10.3.8) and a Mac mini (Server 10.3.8), and it doesn't seem to break anything.

  6. #5
    Mac Freak ncarandang's Avatar
    Join Date
    Apr 2004
    Location
    Makati
    Age
    30
    Posts
    1,395

    Default

    salamat po sa heads up.

  7. #6
    Mac Lover wicket's Avatar
    Join Date
    Apr 2004
    Location
    behind my PB
    Age
    39
    Posts
    379

    Default

    thanks for the heads-up! got it na

  8. #7
    Mac Addict cyberprince's Avatar
    Join Date
    Oct 2004
    Location
    The Philippines
    Age
    31
    Posts
    1,749

    Default

    Thank you for the heads up as well! I always seem to miss these kind of stuff! It's going to take over an hour on my dial-up connection but what the heck!

  9. #8
    Apple Genius Macmon's Avatar
    Join Date
    Apr 2004
    Location
    QC
    Age
    44
    Posts
    2,029

    Default

    Had done a restart and somehow it seems it does not want to restart when it powered down. But after pushing the power switch, two times then it restarted properly. That gave me a scare.... Now everythings OK.

  10. #9
    Administrator elbert's Avatar
    Join Date
    Apr 2004
    Location
    A, A
    Posts
    13,831

    Default

    encountered some problems in my wife's tangerine. After the update, Safari wouldn't run. I don't know if other apps were affected. I restarted, repaired disc permissions and it's fine now.

    ALWAYS repair permissions after any SW update or install.

  11.   



 

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •