Apple Security Update Posted
patpro writes "Apple has just released a security update for Mac OS X. It includes Apache 1.3.23, OpenSSH 3.1p1, PHP 4.1.2, rsync 2.5.2, and sudo 1.6.5p2 (among other things). For the moment it's available only via the Software Update pane in System Preferences, but it should be available later at the Apple Downloads Page."
I miss my folder popping open... it really rocked. especially when draggin' and droppin' oh well... macosX kicks macos9's butt in all other areas (especially running *nix apps ;-) ).
Sig you!
Ok, sure. I'll connect a Mac OS 9 box to the net and let's see if you can get in. =)
Other than that, these same updates were available from Red Hat between 2 and 4 weeks ago depending on the package. Apple could be a little faster on the uptake, especially with security patches.
This is constructive criticism, and nothing more.
Do not touch -Willie
This update will replace the current PHP module you have installed.
Many people use a version of the Apache PHP module compiled for OS X by Marc Liyanage that has PDF/Postgres/curl/gd, etc. enabled, rather than the stock Apple installed module.
After applying the update, you will need to reinstall the Liyanage module. It only takes 3 minutes. The instructions and download are located here:
http://www.entropy.ch/software/macosx/php/
<?php while ($self != "asleep") { $sheep_count++; } ?>
I keep reading about update problems, but until now, everything has always worked for me.
This one bombed though. It downloaded, and then I got a message saying that none of the patches had been installed due to "an error".
The system console was no more explicit. There were reports of problems on Macnn.com as well.
Has anyone installed it successfully on their system?
Ted
I'm affraid the rsync 2.5.2 Apple just released for OSX is still vulnerable...
5
the FreeBSD-SN-02:01 Security Notice reads this :
Port name: rsync
Affected: versions < rsync-2.5.4
Status: Fixed.
Incorrect group privilege handling, zlib double-free bug.
URL:http://online.securityfocus.com/bid/428
URL:http://www.rsync.org/
so what ? is MacOSX immune to the "Incorrect group privilege handling" bug of rsync < 2.5.4 or does Apple just released a buggy sec. update ? This bug appears to be known for 3 weeks now...
This is from Apple's update page:
Security Update April 2002 includes the following updated components which provide increased security to prevent unauthorized access to applications, servers, and the operating system.
OpenSSH v3.1p1
rsync v2.5.2
groff v1.17.2
PHP v4.1.2
sudo v1.6.5p2
mod_ssl v2.8.7
mail_cmds
Not like these sorts of updates should require a reboot but sometimes they do, like with the recent Airport software update.
Hey! another crappy post from everyones favorite genius! Have you considered that if you ran OSX + Mathematica 4.1 you could come up with a bit more accurate results? Oh what what did you say, your results arent based off of numbers? That would make sense because you probably cant even use a calculator. Too much entropy from typing the keys, nano hackers could slip through the cracks and steal your data!
I want 2D games back.
9 was a very secure os believe it or not.
Go away, silly troll. Pray to the cock-obelisk of Bill Gates.
I would dearly love this update, but my damn Software Update thingy's stopped working. Can't connect, although every other program works. Anyone suggest a solution?
If all computers had a 100% chance of getting broken into when connected to a network, ALL computers would be broken into, no matter how long they were online. Simply, this is not true. It's not true for the time, and even ignoring the time, it's not true for many operating systems, or even many individual machines that are left on for a long time.
"The price of freedom is eternal vigilance." - Thomas Jefferson
Has anyone else had this problem? It's been around for quite a while on my PowerMac G4, and no matter how many security updates I install it doesn't change.
When I try running SSH, I get
OpenSSL version mismatch. Built against 90581f, you have 90602f
So how do I get 90581f, or whatever I actually need?
Thanks for any help.
D
Sure you can get it... it will just take a bit longer since you can't go to scriptkiddies.com and download some script to break into your system.
>Oh, did you know the price of a new x86 system has dropped to $300 with firewire?
Oh, did you realize the Mac isn't going to be a piece of shit?
(btw, how much do you plan to spend on decent editing software?)
At least post as a user next time asshole, so I know who I'm about to make a fool of.
Cinema Tools $999
iMovie 2 $999
iDVD $999
Final Cut Pro $999
Do you think they all have identical developement costs and therefore are all priced the same or do you think Apple might be ripping you off?
Apple recomended additional software:
Adobe After Effects $1999
They are certainly ripping you off with their hardware cost:
At least $2500 for a slow G4. At least wait for this to get some decent hardware at a fair price.
And what can you use this for? Home movies, low budget porn and local commercials. You see, you can only burn an hour of video using iDVD. Apple is trying to make you think you are shooting video just like the pros, just like they are trying to make you think that that pricey toy you have is a real computer. And they have you fooled. To the tune of $10,000.
A fool and his money are soon parted. By the way, to me $10,000 is a Beowulf cluster with 50 CPUs, just like Pixar uses, Steve Jobs' other company.
Go pout or LOG IN to respond you bitch assed coward.
If voting were effective, it would be illegal by now.
dude, your list of sw is /fucked/.
imovie comes with a $799 imac.
idvd comes with a $1300 imac.
all the pro stuff is just that, pro stuff
so, yeah, apple charges pro prices for pro soft, and gives the consumer stuff away for free. what a fucking surprise.
london is drowning and i live by river
>At least post as a user next time asshole, so I know who I'm about to make a fool of.
>iMovie $999
>iDVD $999
Are both free, dumbass. Now who's the fool?
>Go pout of LOG IN to respond you bitch assed coward.
Haha, suck shit, wiener boy.
Macs use PC133
Actually my "inexpencive aftermarket" [sic] $49 512 MB PC133 RAM works just fine in my G4 with all the latest firmware updates.
And your point was?
NEXT! ;-)
-- if it was so, it might be; and if it were so, it would be; but as it isn't, it ain't. That's logic - Lewis Carrol
133mhz fsb G4s use pc133. The G4 iMac, TiBook, 168 pin G3 iMac, New iBook and Older G4 towers ALL USE PC100 Memory in either Dimm or Sodimm form factor. They can all use PC133 because it is better than PC100 Cas 322. The firmware update disabled any memory that did not run at least that speed.
If voting were effective, it would be illegal by now.
PC133 is faster memory than PC100 cas 322. So the firmware did not disable it. Here is the breakdown:
PC66 Cas 222 is the same as PC100 cas 333. Except for minor architectural changes in reguards to reporting it's speed to the bios.
PC100 cas 222 is Identicle to PC133 cas 333.
PC133 cas 222 can be run as PC150 cas 333.
PC150 cas 222 can be run at PC166 cas 333.
You have been kept in the dark about your hardware. If Apple hardware was in any way tweakable, you would understand how much crap you have been fed. Is your G4 a 100mhz fsb version or a 133mhz fsb version?
If voting were effective, it would be illegal by now.
All but the first two G4s (the Yikes!, which was a G3 MB and the Sawtooth both had 100 MHz busses) have 133 MHz system busses and use PC133 RAM. I have a "Digital Audio" G4, with a 133 MHz bus. It wont run on PC100 no matter what the cas rating is. Some chips from dealers are mislabeled also and this is where the firmware problems arose. The firmware was catching PC100 RAM labeled as 133.
I know about hardware, do you think because I use Macs I haven't had any experience building computers? I rebuild Macs and PCs all the time. I have 12 Macs and several PCs I built. Not every one has the bargan basement mentality that a lot of PC users have. Sometimes cheap is just junk.
Also you are over simplifying the RAM issues, and RAM is not always interchangeable. The Apple firmware update only disabled RAM that was not up to spec. Some of this RAM could be reprogramed to spec, but did not leave the factory that way. Apple doesn't expect people to buy memory from them, they only expect people to use qualified parts. I always buy the cheapest memory I can find and never have any problems. But I dont buy junk either. There is a difference. I also don't try to put PC100 DIMMs in where it calls for PC133. What's the point? Some memory controllers are fussier than others. Try and put out-of-spec RAM in a SUN or SGI for instance!
-- if it was so, it might be; and if it were so, it would be; but as it isn't, it ain't. That's logic - Lewis Carrol
Sigh. We know you are jealous. A "Beowulf cluster with 50 CPUs" is a *toy*. I'll give you a *big* hint. If it's got x86 in it, IT IS A TOY - cheap, antiquated hardware that can play some games. If you want a "real" computer you'll need to look into some "real" CPUs - PowerPC (designed from the ground up to be a nice, "modern" CPU - not a hacked-up 4004), Sparc series, Alpha (64 bit for 6 years now?).
Face it - you don't know what the hell you are talking about.