Security Updates in Mac OS X 10.2.3 Updater

From this Apple KBase article,

"Mac OS X 10.2.3 Software Update contains fixes for the following potential security issues:

* fetchmail: Fixes CAN-2002-1174 and CAN-2002-1175 which could lead to a potential denial of service when using the fetchmail command-line tool. fetchmail is updated to version 6.1.2+IMAP-GSS+SSL+INET6

* CUPS: Provides fixes for the following potential issues that could be exploited remotely when Printer Sharing is enabled. Printer Sharing is not enabled by default on Mac OS X or Mac OS X Server.

CAN-2002-1383: Multiple Integer Overflows
CAN-2002-1366: /etc/cups/certs/ Race Condition
CAN-2002-1367: Adding Printers with UDP Packets
CAN-2002-1368: Negative Length Memcpy() Calls
CAN-2002-1384: Integer Overflows in pdftops Filter and Xpdf
CAN-2002-1369: Unsafe Strncat Function Call in jobs.c
CAN-2002-1370: Root Certificate Design Flaw
CAN-2002-1371: Zero Width Images in filters/image-gif.c
CAN-2002-1372: File Descriptor Resource Leaks

"In addition, Mac OS X 10.2.3 provides the following enhanced security features:

* Random initialization of TCP Timestamp: This enhancement was submitted by Aaron Linville through the Darwin open source program. It prevents a remote entity from discovering how long a machine has been up based on the ID in the TCP packets.

* Disk Utility now provides the option to zero data on the disk, providing an additional method for securing information.

[Brian Nakamoto]

Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Security · This month in the archive