Apple Patches Security Flaw in Terminal.app
Currawong writes "Apple has posted Security Update 2002-09-20 for Mac OS X 10.2 and above in Software Update, fixing a security hole in Terminal.app which could 'allow an attacker to remotely execute arbitrary commands on the user's system.' Apple also has a useful page listing all the security updates with a short summary and links to what they patch."
Not knowing much about 10.2, how do they handle severe security patches like this? Are users automagically adviced to install or is there an "OS update" type page they need to visit frequently?
Just curious.
Jouni
Jouni Mannonen | Game Designer, Consultant
Today must have an "A" in it....
I found this bug 2002/09/20, and start to make report for Apple.
In fortunate thing, Apple fixed this bug and begin to distribute updater.
Since Apple fixed this serious bug, I decided to open to the public.
This is very serious security bug.
All Jaguar user should update immediately.
I prepared the test easy here.
If link below is clicked, a Terminal will start and "ls -la" command will be executed by your authority.
telnet://|ls -la
Your use of updater vanishes this brittleness.
name:Taiyo FUJII
E-Mail:taiyo@vinet.or.jp
Sorry, I don't have slashdot account.
This update replaces the entire Terminal.app.
It is now 528kb in size, as opposed to the previous 439kb.
I've also noticed that it launches noticably faster after the update. Perhaps Apple added some tweaks in addition to the security changes.
(no, it isn't the updated prebindings. I just did that myself this morning).
After installing this update, all text in Terminal.app appears in reverse.
The terminal.app is so slow, even after this patch it opens like a dog. thats why I boot to gentoo ppc, and use my trusty xterm. that launches as fast as I click on it. And now that mol supports macosx I will never have to reboot again! I love linux.
keanmarine.com
Liar
I get the following error when opening the terminal now: /usr/share/init/tcsh/rc: No such file or directory.
Welcome to Darwin!
Anyone know why this would happen?
I didn't know a thing about this exploit until I heard there was a patch for it. Not to bash or anything, but if it was MS, it would have been all over the news before the fix came out. Guess there's something to be said for being the minority player after all :)
Come to the University of Mars! Classes starting soon!
I am a homosexual. I bought an Apple computer because of its well earned reputation for being "the" gay computer. Since I have become an Apple owner, I have been exposed to a whole new world of gay friends. It is really a pleasure to meet and compute with other homos such as myself. I plan on using my new Apple computer as a way to entice and recruit young schoolboys into the homosexual lifestyle; it would be so helpful if you could produce more software which would appeal to young boys. Thanks in advance.
with much gayness,
Father Randy "Pudge" O'Day, S.J.
Same post every thread. This guy's a tool.
There should be a way that Slashcode can recognize this message and mod it down.
you think paying too much for hardware makes you open minded? more like absent minded and open walleted. and os x isnt all that. freebsd ma man, is a lot better. sorry, you like a creamy desktop for your little app while you pretend to do work. lol.
people hate apple because the advertising is offensive, and full of lies. death to you, death to steve jobs, the THIEF, death to most apple users, ill chose a few to keep. death to apple, death to motorola, death to chris galvin for still making the ppc.
...My MS Powerpoint no longer acts properly. It ignores many of the keyboard commands, and the paste command is dimmed. Same thing on my G4 at home after I updated. AND, the dock magnification has become touchy. Anyone else have these problems?