Slashdot Mirror


Apple Patches Kaminsky DNS Vulnerability

Alexander Burke writes "Apple has just released Security Update 2008-005, which patches BIND against the Kaminsky DNS poisoning issue. 'This update addresses the issue by implementing source port randomization to improve resilience against cache poisoning attacks. For Mac OS X v10.4.11 systems, BIND is updated to version 9.3.5-P1. For Mac OS X v10.5.4 systems, BIND is updated to version 9.4.2-P1.' It also closes the script-based local privilege escalation vulnerabilities, the most common examples of which were ARDAgent and SecurityAgent, and addresses other less-publicized security issues as well." A few days back we noted Apple's tardiness in fixing their corner of this Net-wide issue.

4 of 89 comments (clear)

  1. No patch for OS X 10.3 ? by Katchina'404 · · Score: 4, Interesting

    As much as I love Apple, it bothers me that they do not release security patches for versions earlier than n-1 (where n is the current release).

    Mac OS X 10.3 server dates back to October 2003 (http://www.apple.com/pr/library/2003/oct/08pantherserver.html), so it's just short of 5 years. It's not THAT old, especially for a server products that's likely to be used in some SMEs.

    Or is 10.3 not affected ?

    --
    Ceci n'est pas une signature
  2. Re:They might have been slow... by maxume · · Score: 4, Interesting

    They were notified in January.

    --
    Nerd rage is the funniest rage.
  3. Maybe they took the time to get it right? by homesnatch · · Score: 5, Interesting

    Someone mentioned that Apple's delay was due to the patch causing a problem with some environment... Maybe Apple had to take the extra time to get it right.

    I would have preferred that Redhat did as well... The Redhat ES 4 patch for BIND left a couple of my DNS domains offline for a few hours.

  4. DNS patch causes BIND blunder by MacColossus · · Score: 5, Interesting

    http://www.zdnet.com.au/news/security/soa/DNS-patch-causes-BIND-blunder/0,130061744,339290928,00.htm Could this have been what took Apple so long? Not as entertaining as posting "Apple sucks", but worth a look nonetheless.