Slashdot Mirror


Apple Still Has Not Patched the DNS Hole

Steve Shockley notes an article up at TidBITS on Apple's unexplained failure to patch the DNS vulnerability that we have been discussing for a few weeks now. "Apple uses the popular Internet Systems Consortium BIND DNS server, which was one of the first tools patched, but Apple has yet to include the fixed version in Mac OS X Server, despite being notified of vulnerability details early in the process and being informed of the coordinated patch release date."

9 of 296 comments (clear)

  1. Typical Apple Situation by Anonymous Coward · · Score: 5, Funny

    Waiting for the port.

  2. The patch is undocumented by commodoresloat · · Score: 5, Funny

    The problem is that they didnt apply the patch to the OS; they applied a patch directly to the Reality Distortion Field, ensuring that this isn't a vulnerability in the first place.

  3. Mac OS X ...Server? by sexconker · · Score: 5, Funny

    Wait, what?

    1. Re:Mac OS X ...Server? by Anonymous Coward · · Score: 5, Funny

      Wow, sounds great, tell me more about the security, i want to use their super-slick interface for my DNS servers.

  4. Comment removed by account_deleted · · Score: 5, Funny

    Comment removed based on user account deletion

  5. Re:t3h horror! by Annymouse+Cowherd · · Score: 5, Funny

    I would bet it's about as many as are being used as servers, which is not many.

  6. Re:t3h horror! by Anonymous Coward · · Score: 5, Funny

    I'm not sure. But what I do know is that the patch is going to require a hardware upgrade; Apple would have it no other way.

    [runs and hides]

  7. Re:t3h horror! by JanneM · · Score: 5, Funny

    Either that, or a $20 charge for "new features"...

    Come now, give Apple some credit. This isn't just some run-of-the-mill bug, this is a serious security issue that could cause their customers some serious harm if not fixed.

    I'd expect $100 at least; or perhaps they'll introduce the innovative "iLease", with a "lease to own" path for the fixed bug where it's patched permanently on your server after only three years of monthly bug fix rental.

    --
    Trust the Computer. The Computer is your friend.
  8. Lawyered up by markdowling · · Score: 5, Funny

    Why patch when you can tell your lawyers to issue cease and desist letters to everybody - starting with that Kaminsky guy