Security Updates in Mac OS X 10.2.3 Updater
"Mac OS X 10.2.3 Software Update contains fixes for the following potential security issues:
* fetchmail: Fixes CAN-2002-1174 and CAN-2002-1175 which could lead to a potential denial of service when using the fetchmail command-line tool. fetchmail is updated to version 6.1.2+IMAP-GSS+SSL+INET6
* CUPS: Provides fixes for the following potential issues that could be exploited remotely when Printer Sharing is enabled. Printer Sharing is not enabled by default on Mac OS X or Mac OS X Server.
CAN-2002-1383: Multiple Integer Overflows
CAN-2002-1366: /etc/cups/certs/ Race Condition
CAN-2002-1367: Adding Printers with UDP Packets
CAN-2002-1368: Negative Length Memcpy() Calls
CAN-2002-1384: Integer Overflows in pdftops Filter and Xpdf
CAN-2002-1369: Unsafe Strncat Function Call in jobs.c
CAN-2002-1370: Root Certificate Design Flaw
CAN-2002-1371: Zero Width Images in filters/image-gif.c
CAN-2002-1372: File Descriptor Resource Leaks
"In addition, Mac OS X 10.2.3 provides the following enhanced security features:
* Random initialization of TCP Timestamp: This enhancement was submitted by Aaron Linville through the Darwin open source program. It prevents a remote entity from discovering how long a machine has been up based on the ID in the TCP packets.
* Disk Utility now provides the option to zero data on the disk, providing an additional method for securing information.
[Brian Nakamoto]
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?