Apple Security Update 2002-03-24 for Mac OS X is Out
Security Update 2002-03-24 addresses a Samba vulnerability which could allow unauthorized remote access to the host system. The built-in Windows file sharing is based on the open source technology called Samba and is off by default in Mac OS X.
OpenSSL is also updated to address an issue in which RSA private keys can be compromised when communicating over LANs, Internet2/Abilene, and interprocess communication on local machine.
It is recommended that all users install this Security Update.
Here are the details on the security update from an Apple bulletin:
Security Update 2003-03-24 [...] contains fixes for recent vulnerabilities in:
OpenSSL: Fixes CAN-2003-0147, a timing attack on RSA keys.
Samba: Fixes CAN-2003-0085 and CAN-2003-0086 which could allow unauthorized remote access to the host system. The built-in Windows file sharing in Mac OS X is based on Samba. Windows file sharing is off by default in Mac OS X, but it is recommended that all users install this Security Update.
Note: This update only applies the security fixes to the currently-shipping 2.2.3 version of Samba on Mac OS X 10.2.4, and the Samba version is otherwise unchanged. The presence of the following file indicates that the update has been applied: /Library/Receipts/SecurityUpd2003-03-24.pkg
Affected systems: Mac OS X 10.2.4 and earlier and Mac OS X Server 10.2.4 and earlier
System requirements: Mac OS X 10.2.4 or Mac OS X Server 10.2.4
Customers with earlier Mac OS X versions are encouraged to either upgrade to Mac OS X 10.2.4, or visit the Samba and OpenSSL web sites for information on the available fixes.
We updated four G4 Cubes, two iBook 500s, iBook 700, iMac G4 800 and a PowerBook G4 800 with no problems.
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?