Apple Patches Security Flaw in Terminal.app
Currawong writes "Apple has posted Security Update 2002-09-20 for Mac OS X 10.2 and above in Software Update, fixing a security hole in Terminal.app which could 'allow an attacker to remotely execute arbitrary commands on the user's system.' Apple also has a useful page listing all the security updates with a short summary and links to what they patch."
Not knowing much about 10.2, how do they handle severe security patches like this? Are users automagically adviced to install or is there an "OS update" type page they need to visit frequently?
Just curious.
Jouni
Jouni Mannonen | Game Designer, Consultant
I found this bug 2002/09/20, and start to make report for Apple.
In fortunate thing, Apple fixed this bug and begin to distribute updater.
Since Apple fixed this serious bug, I decided to open to the public.
This is very serious security bug.
All Jaguar user should update immediately.
I prepared the test easy here.
If link below is clicked, a Terminal will start and "ls -la" command will be executed by your authority.
telnet://|ls -la
Your use of updater vanishes this brittleness.
name:Taiyo FUJII
E-Mail:taiyo@vinet.or.jp
Sorry, I don't have slashdot account.
This update replaces the entire Terminal.app.
It is now 528kb in size, as opposed to the previous 439kb.
I've also noticed that it launches noticably faster after the update. Perhaps Apple added some tweaks in addition to the security changes.
(no, it isn't the updated prebindings. I just did that myself this morning).
The terminal.app is so slow, even after this patch it opens like a dog. thats why I boot to gentoo ppc, and use my trusty xterm. that launches as fast as I click on it. And now that mol supports macosx I will never have to reboot again! I love linux.
keanmarine.com
Liar
I get the following error when opening the terminal now: /usr/share/init/tcsh/rc: No such file or directory.
Welcome to Darwin!
Anyone know why this would happen?
I didn't know a thing about this exploit until I heard there was a patch for it. Not to bash or anything, but if it was MS, it would have been all over the news before the fix came out. Guess there's something to be said for being the minority player after all :)
Come to the University of Mars! Classes starting soon!
why dont you tell us about a sytem which doesnt have security patches we all would want to use?
Mac OS9.
Its these ignorant people that love to keep their minds closed and keep runing sites like ihateapple.com
I like how gay PC users always post things about gay mac users. You are posting about being gay because you are, faggot
Same post every thread. This guy's a tool.
There should be a way that Slashcode can recognize this message and mod it down.
...My MS Powerpoint no longer acts properly. It ignores many of the keyboard commands, and the paste command is dimmed. Same thing on my G4 at home after I updated. AND, the dock magnification has become touchy. Anyone else have these problems?