Slashdot Mirror


Security Update 2004-02-23 Released

dbesade writes "Apple has released a security update for Mac OS X. The update includes changes to disk arbitration, IPsec, the point-to-point protocol, and tcpdump. As usual the changes have not been posted to the Apple Support Website."

87 comments

  1. IPSec working.. by -tji · · Score: 4, Informative

    I am not sure what they changed in IPSec, but I installed the updates and my VPN connections are still working fine to a Check Point VPN-1 device.

    I looked through the man page for racoon.conf, and didn't see any functionality updates mentioned there. I was hoping they had added patches for NAT Traversal or xauth.

    1. Re:IPSec working.. by Anonymous Coward · · Score: 1, Informative
      It's probably the fix for unauthorized deletion of IPsec (and ISAKMP) SAs in racoon as racoon now contains the string "ignore information because the message has no hash payload" which is from the patch.

      NAT-T is supported by Mac OS X, however it's not interoperable with anything apart from Mac OS X as Apple chose to use their own NAT-T Vendor ID (which is used for NAT-T detection) and also they have implemented the latest versions of the NAT-T and udp-encaps drafts only, which nobody else uses.

  2. small download by billbaird · · Score: 3, Informative

    only 1.6 megs, yippee!!

    1. Re:small download by edalytical · · Score: 4, Informative

      Software Update reports it's 5.1 MB, but I'm still running Jag. I'm sure it makes a differences.

      --
      Win a signed Stephen Carpenter ESP Guitar from the Deftones: http://def-tag.com/?r=0008781
    2. Re:small download by nocturbulous · · Score: 1

      There are separate Jag and Panther updates

  3. Re:Why didn't you post today's updates by IAmATuringMachine! · · Score: 5, Insightful

    Slashdot isn't quite the place to come for Windows news, but occasionally makes with the scoop. BSD has its own section. Linux typically makes the front page most of the day. Any other questions?

    Why do people come to the Mac section to bitch that there is Mac news in it?

    --
    "Computer Science is no more about computers than astronomy is about telescopes."
    -E. W. Dijkstra
  4. Re:Why didn't you post today's updates by justMichael · · Score: 4, Insightful

    You do relaize that you are reading apple.slashdot.org, right?

    You can find *BSD info here, the linux stuff is pretty much everywhere and Windows has moved to a monthly cycle, so you need to wait a couple more weeks and check here ;)

  5. It still feels weird... by readpunk · · Score: 4, Interesting

    It still feels weird wondering if these MAC issues also mean there are changes/upgrades to be made on *nix systems.

    --

    ./revolution
    1. Re:It still feels weird... by Mr.+Darl+McBride · · Score: 3, Interesting

      Most of those have already been patched in other Unices. I've never seen it stated as policy, but Apple seems to bundle local exploit fixes for scheduled updates, saving remote exploits for the surprise updates.

    2. Re:It still feels weird... by Anonymous Coward · · Score: 1, Funny

      Who the fuck modded this interesting?

    3. Re:It still feels weird... by beegle · · Score: 5, Funny
      By MAC, are you referring to the privilege separation of Mandatory Access Control, Ethernet's Medium Access Control (aka "hardware address"), or something else?

      The article was referring to Macintosh (or Mac) issues, and I'm wondering why you're capitalizing the word.

      --
      --
    4. Re:It still feels weird... by hexghost · · Score: 1

      Uh, is this a troll or do you have any evidence? Apple's had an average turnaround on security fixes of about a week, if not shorter.

    5. Re:It still feels weird... by JDWTopGuy · · Score: 4, Funny

      MAC: Recursive acronym for the mental disorder "MAC Always Capitalized". Annoying, but not dangerous.

      --
      Ron Paul 2012
    6. Re:It still feels weird... by readpunk · · Score: 1, Funny

      Although incorrect, I felt like making the word stand out. If it confused you, I would reference the context of the post. It makes it pretty clear which mac mAc maC MAc mAC MAC I am talking about.

      --

      ./revolution
    7. Re:It still feels weird... by geoffspear · · Score: 4, Funny

      It's too bad there aren't other ways to make words stand out besides incorrectly capitalizing tHeM.

      --
      Don't blame me; I'm never given mod points.
    8. Re:It still feels weird... by Mr.+Darl+McBride · · Score: 1, Insightful
      Apple's turn-around has been much shorter than a week for remote exploits.

      Mac OS X is quite secure. Please stop trolling.

    9. Re:It still feels weird... by Anonymous Coward · · Score: 0

      wHO aRe YOu tO cAPiTaLIze mE!!!

    10. Re:It still feels weird... by capmilk · · Score: 1

      Yep, that is _really_ very *sad*.

  6. Apple Support changes list... Tuesday by Gogo+Dodo · · Score: 4, Informative
    The Security Updates page trails by about a day so the list of changes should be up on Tuesday.

    All of Apple Support things seems to trail by about a day. Things must be published at a set schedule.

    1. Re:Apple Support changes list... Tuesday by ptolemu · · Score: 1

      Does the OS X automatic updater pick up these updates? You'd think if anything they'd ensure this feature would at least do its job for those who don't visit the Apple site on a regular basis, not to mention check for updates.

    2. Re:Apple Support changes list... Tuesday by Demolition · · Score: 3, Informative

      Yes, these updates automatically appear in Software Update. In fact, Security Updates usually appear in Software Update before they appear on Apple's website. The following day, a standalone downloadable updater is made available.

      D.

  7. Works fine so far... by Anm · · Score: 1, Informative

    PowerBook 800Mhz DVI

    1. Re:Works fine so far... by skinfitz · · Score: 4, Funny

      I'll see your Powerbook and raise you 200Mhz.

    2. Re:Works fine so far... by batobin · · Score: 3, Funny

      I'll see your GHz and raise you a quarter.

    3. Re:Works fine so far... by Anonymous Coward · · Score: 0

      I'll call. Whatcha got?

      Oh, wait.

    4. Re:Works fine so far... by burns210 · · Score: 1

      I'll see your 1ghz, and'll raise you 512meg of RAM!

    5. Re:Works fine so far... by bcjanes · · Score: 1

      You loose Powerbook 1Ghz here :)

      --
      Linux is unix training wheels, while BSD *is* unix.
  8. Re:Why didn't you post today's updates by NanoGator · · Score: 1

    "Slashdot isn't quite the place to come for Windows news"

    Windows news appears on Slashdot ad nauseum. The problem is getting anything out of it besides "Microsoft is evil/incompetent/arrogant."

    --
    "Derp de derp."
  9. Re:Why didn't you post today's updates by justMichael · · Score: 2, Insightful
    Doesn't matter what section it is, it's on the first page anyone sees.

    Yeah, as long as you are looking at http://apple.slashdot.org/

    Maybe I'm missing something, but the content I get at http://slashdot.org/ is:

    US Army Scraps Comanche Helicopter
    Posted by simoniker on 2004-02-23 17:35

    Developers: Firebird Relational Database 1.5 Final Out
    Posted by simoniker on 2004-02-23 16:46

    Science: Defending Earth From Asteroids With MADMEN
    Posted by simoniker on 2004-02-23 16:01

    Book Reviews: Learning Unix for Mac OS X Panther
    Posted by timothy on 2004-02-23 15:16

    The only one that is Apple related is the book review.

    Yes, I know he was trying to be an ass, that doesn't mean I have to stay quiet. Maybe he didn't realize he wasn't on the main page, it seems like an easy mistake ;)
  10. Re:Why didn't you post today's updates by narftrek · · Score: 1

    Oh MY BAD. Sorry I surf /. with ALL articles shown. I wouldn't want to leave out anybody. Not even the Mac fans :)

  11. More info here by kaan · · Score: 2, Informative

    From this support page at apple.com:

    Security Update 2004-02-23 delivers a number of security enhancements and is recommended for all Macintosh users. This update includes the following components:

    DiskArbitration
    IPSec
    Point-to-Point-Protocol
    Safari

    Additionally, Security Update 2003-11-19 has been incorporated into this security update. Those components are:

    gm4
    groff
    Mail w/CRAM-MD5 authentication
    OpenSSL
    Personal File Sharing
    QuickTime for Java
    zlib "gzprintf()" function

    1. Re:More info here by kaan · · Score: 2, Informative

      oops, posted the wrong link before... at a glance, it looks like it contains the same information.

      here is the correct page for 10.3.x at apple.com

  12. Re:Why didn't you post today's updates by Anonymous Coward · · Score: 2, Informative

    Or you could go into your prefs and turn OFF the apple stuff...

  13. Re:changes to..... by hard-mac · · Score: 2, Interesting

    and so far detecting some changes to: sshd sendmail slogin passwd cron top

  14. Re:Typical by Anonymous Coward · · Score: 0

    If you don't like Apple updates, then stay out of apple.slashdot.org. It's not like they are on the front page or something.

    You deserve to be modded down for this stupid crap.

  15. Re:Problem with security update don't install. by steeviant · · Score: 2, Interesting

    This sounds like one of those trolls where you change the problem and computer model to reflect the story you're posting about. Like the 'freelance gig' one.

  16. Re:Problem with security update don't install. by davids-world.com · · Score: 1, Informative
    Don't know what your problem is. I never had problems installing an update, I never crashed my machine completely with an official Apple OS X system, or with third-party applications. I never had a virus, and no security breaches either. Now, from my (too) many years of Windows computing (95, NT, 2000), I do know what a crash, a virus or the common 'system slowdown'/DLL hell looks like.

    Maybe your friend was messing around with system files, deleting things from /System or /Library??

  17. Re:Problem with security update don't install. by mattnl · · Score: 0, Troll

    How did it take 5 hours to do: Software Update > Install

  18. Re:Problem with security update don't install. by Anonymous Coward · · Score: 0

    So, what is this? A slight variation on the "17 Meg File" troll-bot?

  19. Re:Typical by narftrek · · Score: 0, Funny

    Crowd: We've got a Mac Zealot! Burn 'er!!
    Knight: But how do you KNOW she's a Mac zealot?
    Crowd: Cause she's posting AC?
    Knight: And what do we do with Mac zealots?
    Crowd: BURN 'ER!!!!

    C'mon people really, you'd bash a Microsoft story in a heartbeat........

  20. Files in distribution by Anonymous Coward · · Score: 5, Informative

    ./System/Library/Frameworks/CoreFoundation.framewo rk/Versions/A/CoreFoundation ./System/Library/Frameworks/CoreFoundation.framewo rk/Versions/A/Resources/Info.plist ./System/Library/Frameworks/CoreFoundation.framewo rk/Versions/A/Resources/version.plist ./System/Library/PrivateFrameworks/DiskArbitration .framework/Versions/A/Resources/Info.plist ./System/Library/PrivateFrameworks/DiskArbitration .framework/Versions/A/Resources/version.plist ./usr/lib/libpcap.A.dylib ./usr/sbin/diskarbitrationd ./usr/sbin/pppd ./usr/sbin/racoon ./usr/sbin/tcpdump

  21. Re:Typical by Anonymous Coward · · Score: 3, Funny

    Congratulations, you've figured out that when you post flamebait it will be moderated as such.

    For a novel experiment, try posting something insightful or informative and see what happens!

  22. Re:Why didn't you post today's updates by Lars+T. · · Score: 1, Funny
    Windows news appears on Slashdot ad nauseum. The problem is getting anything out of it besides "Microsoft is evil/incompetent/arrogant."

    IOW there is no news about Microsoft on Slashdot.

    --

    Lars T.

    To the guy who modded me down from perfect to terrible Karma - Apple haters still suck

  23. Update just screwed me by strazi · · Score: 1, Informative

    My powerbook 12in 1ghz is booting into a command prompt. Last thing it says is "Root device is mounted read-only" and "Filesystem checks skipped." I cant get it to boot off of any cd, Panther, Jaguar,or Diskwarrior. Was fine until I rebooted after this security update. Umm, HELP!

    1. Re:Update just screwed me by strazi · · Score: 2, Informative

      Okay, got it fixed. Good thing I had another computer to look up things about Open Firmware and how to reset stuff.

    2. Re:Update just screwed me by Phroggy · · Score: 1

      Last thing it says is "Root device is mounted read-only"

      This is normal; it must be remounted read-write before you can do anything with it. Normally this is done automatically by a script, but if you're in single-user maintenance mode, the system assumes there could be a problem (e.g. maybe the hard drive is fried) and you might want to read some data off the disk before writing anything to it.

      and "Filesystem checks skipped."

      OSX 10.3 uses journaling, so checking the filesystem for errors isn't needed.

      What was the fix?

      --
      $x='S24;r)>63/* h@<5+oZ)32"5cz';$me='phroggy'x$];
      $x=~y+ -xz+\0-Tx+;print$_^chop$me for split'',$x;
    3. Re:Update just screwed me by strazi · · Score: 2, Informative

      "reset-nvram" and then "reset-all" in open firmware, no idea what caused it though

  24. kbase articles by blb · · Score: 5, Informative

    The kbase articles are online, but not mentioned anywhere yet:
    update for 10.2 server
    update for 10.3 client
    update for 10.3 server
    Not sure where 10.2 client is yet...

    1. Re:kbase articles by blb · · Score: 1
  25. Re:Why didn't you post today's updates by brasten · · Score: 5, Funny

    As already noted, Linux, *BSD, etc are already well covered on Slashdot. As far as Windows, have YOU ever tried keeping up with their updates/patches? Dear God...

  26. Re:Typical by Anonymous Coward · · Score: 2, Insightful

    This isn't about bashing a story, this is about you deciding it isn't news suitable for posting on apple.slashdot.org.

    It interests Macintosh users, so it's on topic.

    Likewise, any Microsoft story would be relevent on microsoft.slashdot.org if there was one.

    The conclusion remains inescapable: If you're not interested in Apple/Macintosh news, do not pay attention to apple.slashdot.org.

    It isn't as if this was a front page story. Then, you might have reason to complain -- but it would still be offtopic for the discussion associated with the story.

  27. Re:Typical by Anonymous Coward · · Score: 0

    If you talk like a bitch, you'll get slapped like a bitch. Go away, whiner.

  28. Re:Problem with security update don't install. by Ohreally_factor · · Score: 4, Informative

    You took the bait, and now you look like a schmuck. This is the 20th time I've seen this troll on slashdot, and I'm not an everyday vistor/poster.

    --
    It's not offtopic, dumbass. It's orthogonal.
  29. I fold. by krray · · Score: 2, Funny

    Powerbook 667Mhz, crap hand again. I fold.
    No issues otherwise... :)

    1. Re:I fold. by dcocos · · Score: 1

      Actually your pair of 6's beats the pair of 0's and if I remember the rules corrrectly cards (or Mhz) talk.

  30. Re:Problem with security update don't install. by fredmosby · · Score: 3, Funny

    After using Mac OS X for four years I couldn't help but laugh at this troll. Only a windows user would think the problems listed are even remotely plausible.

  31. too manny acronyms by fredmosby · · Score: 1

    what does IOW mean?

    1. Re:too manny acronyms by Phroggy · · Score: 1

      what does IOW mean?

      In Other Words

      --
      $x='S24;r)>63/* h@<5+oZ)32"5cz';$me='phroggy'x$];
      $x=~y+ -xz+\0-Tx+;print$_^chop$me for split'',$x;
  32. Re:Problem with security update don't install. by baryon351 · · Score: 1

    It is. Part of it's taken from old slashdot apple trolls, and part from a post on Amiga.org.

    Personally I found the cat vs dog version of the "freelance gig" mac vs PC troll absolutely hilarious. Wish I could find a link to that one.

  33. Safari Update by Anonymous Coward · · Score: 1, Informative

    The "Safari" update is actually an update to WebCore and JavaScriptCore, the frameworks that Safari is built on top of that are part of Panther.

  34. Re:Problem with security update don't install. by xKlintx · · Score: 1, Insightful

    You must be smoking rock. The update took under 5 minutes to download, install, and reboot. I love my G5 more than any Dell I've ever had. If you want to talk about a laundry list of problems, I'll start talking about my 450mhz inspiron laptop. Worst piece of computational garbage I've ever owned.

    I'm not the kind of person who likes to (nor can I afford to!) drop money on a new computer every few months. I like to buy things, and have them last. Apple products last. Of the 4 years I used that Dell, it was seriously defective for over 3 of them.

    --
    If you don't like it, fight me.
  35. Yes, but does it.. by dave1212 · · Score: 5, Funny
  36. DiskArbitration by stoffel · · Score: 2, Interesting

    What does that mean??? or should I RTFM :-D

    1. Re:DiskArbitration by squiggleslash · · Score: 2, Funny
      Several makes of hard drive have recently come under scrutiny because of critical failures that can cause the loss of substantial amounts of data. These problems, as well as massively inconveniencing the buyer of the disks, cause problems up and down the line because it can be difficult to replace hard drives with ones guaranteed to work. Complaints and class action lawsuits, greeted by blanket denials and damage limitation exercises through PR rather than technical solutions, have become commonplace.

      What Disk Arbitration seeks to do is create a trusted third party, an arbitrator, that both the manufacturer and the consumer can use to resolve complaints. While neither party will get exactly what they want, they'll at least involve the costs and effort related to legal action and usually end up with a satisfactory settlement.

      If you ask me, it's a very good idea.

      ;-)

      --
      You are not alone. This is not normal. None of this is normal.
  37. Re:Problem with security update don't install. by Anonymous Coward · · Score: 1, Funny

    Cats

    I don't want to start a holy war here, but what is the deal with you cat fanatics? I've been sitting here on my sofa in front of a cat (a sealpoint siamese) for about 20 minutes now while attempting to get it's attention away from a bug on the floor. 20 minutes. At home, with my labrador cross, which by all standards should be a lot dumber than this cat, the same operation would take about 2 minutes. If that.

    In addition, during this attention seeking attempt, my children's attention is also held by the cat. And everything else has ground to a halt. Even trying to get the remote from my partner fails.

    I won't bore you with the laundry list of other problems that I've encountered while dealing with other cats, but suffice it to say there have been many, not the least of which is I've never seen a cat that fetches as much as it's canine counterpart, despite the cat's faster ambulatory system. My terrier with one ingrown toenail runs consistently faster than this siamese at times, as the cat is often completely asleep. From a productivity standpoint, I don't get how people can claim that the cat is a superior animal.

    Cat addicts, flame me if you'd like, but I'd rather hear some intelligent reasons why anyone would choose to use a cat over other faster, cheaper, more affectionate animals.

  38. Re:Typical by TheRaven64 · · Score: 0, Troll
    For a novel experiment, try posting something insightful or informative and see what happens!

    I tried it. You get moderated as troll...

    --
    I am TheRaven on Soylent News
  39. Re:Problem with security update don't install. by Anonymous Coward · · Score: 0

    Thank you :).

  40. Airport dysfunction by 1010011010 · · Score: 1

    After installing this update, Airport fails to connect reliably, and when it does connect, it's very slow and unpredictable (ping times to the local access point, 6 feet away, vary from 30ms - 200ms).

    --
    Napster-to-go says "Fill and refill your compatible MP3 player", which is a lie. It's not MP3. It's WMA with DRM.
  41. Your Dell by Doc+Squidly · · Score: 1

    Just out of curiosity? What OS was on your 450 Mhz Dell? Windows 95 or 98?

    Not trolling but, doesn't it seem unfair to compare any modern Computer to something that is 5 to 7 years old.

    I could compare my 2.0 Ghz HP Laptop running XP Pro to an iMac I had in '98.

    I love my HP more than that iMac (slow & and what's up with that hockey puck mouse?).

    Not really a fair comparison, is it?

    --
    I think I think, therefore I think I am.
  42. Re:Problem with security update don't install. by Anonymous Coward · · Score: 0

    Ignore it; the 5-hour-install post was just a variant of a troll post that's been showing up in virtually every Mac /. story for years. This troll usually gets modded down to -1 within a few minutes, unless someone comes up with a particularly funny twist on it.

  43. Re:Why didn't you post today's updates by Anonymous Coward · · Score: 0

    Well, for one thing, no one gives a shit about Windows.

    You actually use Windows?

  44. Re:Why didn't you post today's updates by Anonymous Coward · · Score: 0

    You actually use Windows?

    He must be in Soviet Russia. It's always the other way 'round there than it is here.

  45. Installed files by security update by Anonymous Coward · · Score: 0

    ./System/Library ./System/Library/Frameworks ./usr ./System/Library/PrivateFrameworks ./usr/lib ./usr/sbin ./System/Library/Frameworks/CoreFoundation.framewo rk ./System/Library/Frameworks/CoreFoundation.framewo rk/Versions ./System/Library/Frameworks/CoreFoundation.framewo rk/Versions/A ./System/Library/Frameworks/CoreFoundation.framewo rk/Versions/A/CoreFoundation ./System/Library/Frameworks/CoreFoundation.framewo rk/Versions/A/Resources ./System/Library/Frameworks/CoreFoundation.framewo rk/Versions/A/Resources/Info.plist ./System/Library/Frameworks/CoreFoundation.framewo rk/Versions/A/Resources/version.plist ./System/Library/PrivateFrameworks/DiskArbitration .framework ./System/Library/PrivateFrameworks/DiskArbitration .framework/Versions ./System/Library/PrivateFrameworks/DiskArbitration .framework/Versions/A ./System/Library/PrivateFrameworks/DiskArbitration .framework/Versions/A/Resources ./System/Library/PrivateFrameworks/DiskArbitration .framework/Versions/A/Resources/Info.plist ./System/Library/PrivateFrameworks/DiskArbitration .framework/Versions/A/Resources/version.plist ./usr/sbin/diskarbitrationd ./usr/lib/libpcap.A.dylib ./usr/sbin/racoon ./usr/sbin/pppd ./usr/sbin/tcpdump

    Stephan

  46. Works for me. by Raven42rac · · Score: 1

    Works fine on my Powerbook 12" 1ghz 768MB RAM.

    --
    I hate sigs.
  47. Update works fine by PurdueGraphicsMan · · Score: 1

    I'm running a 1Ghz G4 ("Wind Tunnel") :-D

    --


    The guitars sound good, now give me about 10db more on the cow bell.
  48. READ ME--really! by catdevnull · · Score: 1

    Be sure to repair permissions or do any other disk maintenance voodoo that makes you feel best BEFORE applying this (or any other patches) from Apple. I'm pretty sure that's the official line from Apple regarding updates. If it isn't, it should be.

    Immediately after applying the updates, I, and several other at MacFixit.com, reported kernel panics when changing locations on powerbooks. This was fixed by repairing permissions with Disk Utility. The problem was only with 10.3.2 not under 10.2.x. Your mileage may vary. Caveat emptor!

    --

    I might know what I'm talkin' about, but then again, this is Slashdot...
  49. HELP! by Anonymous Coward · · Score: 0

    I'm running OS 10.2.8, and my computer is having some problems. The main thing is that my I cannot click and drag items in the Finder. I've tried everything, from repairing permissions, to optimizing the system, and even trying to go back and load OS 10.2 from CD; it would give up before I could get it loaded. None of these things have worked. I don't know the language for Terminal, so I haven't tried that yet. If anyone has any good ideas, I would really appreciate the help.