Security Updates Released for Panther and Jaguar
ZackSchil writes "Apple has released security updates for both Mac OS X 10.3.1 and, as promised, 10.2.8. The update to 10.3.1 updates OpenSSL and zlib's gzprintf() function. In addition to those updates, the 10.2.8 update contains changes to gm4, groff, Mail w/CRAM-MD5 authentication, Personal File Sharing, and QuickTime for Java. Run Software Update for more information and to install the updates."
fr0sty p1ss bitches...
:)
this fp brought to you by my shiny new 12" powerbook..
snoogans
kate - i love you
I've already installed Security Update 2003-11-19 and QuitTime for Java Update v2.0. No problems so far. Great to see Apple keeping their promise and supporting Jaguar.
Win a signed Stephen Carpenter ESP Guitar from the Deftones: http://def-tag.com/?r=0008781
I tried the update to 10.2.8, and all seems to be well. Thanks to Apple for keeping the older OS's secure. Now if they'd only let us use 3rd party drives with their Disc-recording software in 10.3, it would be golden !! ;-)
Everything still works. I havent seen any killer bugs popping up on macfixit or versiontracker either. Also note that the QT Java update is included - fixed one broken site for me that Panther QT had knocked out.
Oh and a bluetooth update, but my Sony Ericsson already works flawlessly (and still does post-update).
And yes, it does require a restart for all of you running the "Show Off" uptime screen saver.
---- The real Slashdot is still here. You just have to browse at -1 to read the comments.
I spent 800.00 on an Apple laptop purely to test the websites I create two months ago (I'm a web developer and I take QA seriously). It's a pretty big slap in the face to find out that the investment is worthless.
I hope that ome of these patches fixes my lockup issues in 10.2.8
Pretty Pictures!
Yet another piece of evidence showing that Apple doesn't care about security OR stability. You motherfuckers were right, I'm switching to Windows.
Where are all the people who were crying last week about Apple not supporting Jaguar? Huh?!? WHAT DO YOU HAVE TO SAY FOR YOURSELVES NOW!!!
Go ahead and mod me +1 Flamebait, just RECOGNIZE that you people are the FISH that took the bait last week!
So high and mighty with your mod points.
What happened? I'll bet you this was all caused by an incident involving two Apple programmers, hot grits, and Natalie Portman. As Linus Torvalds and the Goatse guy can attest, it's hard to write decent code while blowing your load.
Repeal the DMCA!
I haven't seen this mentioned yet so I'll pass this tidbit along.
SecurityTracker has information on a new sudo vulnerability. Only laptops are affected.
[Zen:~] bmt% softwareupdate -l
Software Update Tool
Copyright 2002-2003 Apple Computer, Inc.
Software Update found the following new or updated software:
! SecurityUpd2003-11-19-1.0
Security Update 2003-11-19, 1.0, 1360K [required] [restart]
[Zen:~] bmt%
~/ $ sudo softwareupdate -i -r
This
Panther breaks the networking GUI that was pretty good in Jaguar. Now, servers you've connected to through browsing in the Finder don't show up on the desktop, and if they're an SMB share, can't be ejected without throwing your powerbook through a window, er, restarting. To get an icon on your desktop that represents a mounted server, you have to know and type in its IP address and protocol, or its precise network name --browsing doesn't work.
The Apple Discussion boards are buzzing with this one. The GUI implementation is horribly confusing to newbies especially, but bad enough for those of us who know what smb:// or afp:// or DHCP actually is. They must be getting a ton of feedback from us aggravated types.
Until this is fixed, no-one I know here at the university will be advised to upgrade to 10.3, despite the many juicy new features and optimization.
Damn those pesky terrorists
Sheesh. There sure is a low amount if interest in this news item. It must have to do with the security reputation of the Apple OS.
:)
Why bother to put up another new electric fence around Fort Knox
Don't blame Durga. I voted for Centauri.
Now they put out "Security Updates for Panther and Jaguar". It's just a little late to save Roy from that pain in the neck, but it's a step in the right direction! Make those big cats safer.
Don't blame Durga. I voted for Centauri.
I ran the update today, and it appears (naive?) that my OpenSSL was not updated. While the date seems accurate, the version is not the suggested update. I know I read somewhere yesterday (I can't find the link again today) that the fix was to update to 0.9.6j, although this is the output on my "updated" g4 with jag:
[akira:~] dema% openssl version
OpenSSL 0.9.6i Feb 19 2003
Any ideas what's up with that?
This is such a non-issue. First, it requires an authenticated sudo event (e.g. someone typed in their sudoers allowed password), the laptop to be put to sleep, then someone to run another sudo command immediately after the system wakes up. This is NOT a critical vulnerability by any standard.
There exists no way of exchanging information without making judgments. --Bene Gesserit Axiom
Note this update also brings Safari up to 1.1.1 (100.1); not sure what changed (still no mention of changes to Safari at the kbase page).
How dare you report that Apple may not have patched something, THE NERVE! You must be modded into oblivion, because this is not the place to post anything critical of Apple, no matter how true.
If they change their minds and fix it after the fact, it becomes "hearsay" as well.
This still doesn't fix the disappearing unattended laptop issue. I've lost 4 notebooks this way!
I was walking into staples and was talking to one of my friends who works there. He noticed some guy walking in with a printer, then he said to me "shit that is the 4th time he has come back with a printer".. then he said, he has the new mac os, none of them would intall on his panther os.
Black Sky
2D Elite Inspired Game
insecure.ws: Safari cookies theft+exploit is not fixed!!
;p
/exploit
the news about the exploit is like one or two days old, and it's not even on slashdot ?? what a shame !
btw: the exploit allows about anyone to steal your cookies, including data about you, passwords, eg online bank accounts etc (or amazon/etc or such) it's quite dangerous there's also a demo here: demo
I did the same thing on my iBook and get the same output:
/usr/bin/ but when I run "which openssl" I get "/sw/bin/openssl" and running "/usr/bin/openssl version" returns "Command not found."
[Adam-Laptop:/usr/bin] user% openssl version
OpenSSL 0.9.7a Feb 19 2003
[Adam-Laptop:/usr/bin] user%
Now, the weird thing is there is openssl command in
Now I have to ask why is this?
Let the anti-empiricists do the beta testing before jumping on any OS X updates in the short term.
Does anyone know if this will help with a Pen Drive problem. Everytime I put my in my new Emac it takes 3 trys to get it to work then it wont even let me put anything in it. The finder just freezes. Pen drive worked on an IMac with 10.2.8