Security Updates in Mac OS X 10.2.3 Updater

From this Apple KBase article,

"Mac OS X 10.2.3 Software Update contains fixes for the following potential security issues:

* fetchmail: Fixes CAN-2002-1174 and CAN-2002-1175 which could lead to a potential denial of service when using the fetchmail command-line tool. fetchmail is updated to version 6.1.2+IMAP-GSS+SSL+INET6

* CUPS: Provides fixes for the following potential issues that could be exploited remotely when Printer Sharing is enabled. Printer Sharing is not enabled by default on Mac OS X or Mac OS X Server.

CAN-2002-1383: Multiple Integer Overflows
CAN-2002-1366: /etc/cups/certs/ Race Condition
CAN-2002-1367: Adding Printers with UDP Packets
CAN-2002-1368: Negative Length Memcpy() Calls
CAN-2002-1384: Integer Overflows in pdftops Filter and Xpdf
CAN-2002-1369: Unsafe Strncat Function Call in jobs.c
CAN-2002-1370: Root Certificate Design Flaw
CAN-2002-1371: Zero Width Images in filters/image-gif.c
CAN-2002-1372: File Descriptor Resource Leaks

"In addition, Mac OS X 10.2.3 provides the following enhanced security features:

* Random initialization of TCP Timestamp: This enhancement was submitted by Aaron Linville through the Darwin open source program. It prevents a remote entity from discovering how long a machine has been up based on the ID in the TCP packets.

* Disk Utility now provides the option to zero data on the disk, providing an additional method for securing information.

[Brian Nakamoto]

Saw something? Send a tip or a correction

The archive ran on reader tips. What did you see, where, and do you want the credit? Something wrong on this page? Say so and it gets fixed.

Read by the editor. You get a copy by email. Never published without your say.

More in Security · This month in the archive