PowerMail 4.2.1 is Out

and available for download. Designed as a robust and sustainable alternative to other Macintosh e-mail applications, PowerMail 4.2.1 is based on the PowerMail Engine, a robust foundation for cross-platform e-mail clients encompassing 10 years of mail and directory experience according to CTM Development. The changes from the previous version (4.1.3) are listed here.

-- Weekend, October 4-5 --

[Update 9a EDT 10/4] Mac OS X 10.2.8 (10/3 version) Combo Standalone Updaters Available: The combo updaters update any version of Mac OS X 10.2-10.2.5 to 10.2.8. They are great for quickly updating new installs of 10.2 or insuring that all necessary updates have been installed. Here are the links to all of the standalone 10.2.8 updaters, including the combos:

Mac OS X Client "Combo" (updating from 10.2 - 10.2.5): The download file is named: "MacOSXUpdateCombo10.2.8.dmg". Not for G5.

Mac OS X Client (updating from 10.2.6 - 10.2.7): The download file is named: "MacOSXUpdate10.2.8.dmg". Not for G5.

Mac OS X 10.2.8 Ethernet/Battery (updating from 10.2.8): The download file is named: "MacOSXUpd10.2.8.dmg". Not for G5.

Mac OS X Server (updating from 10.2.6): The download file is named: "MacOSXServerUpdate10.2.8.dmg". Not for G5.

Mac OS X Server "Combo" (updating from 10.2 - 10.2.5): The download file is named: "MacOSXSrvrUpdCombo10.2.8.dmg". Not for G5.

Mac OS X Update (G5) v10.2.8(G5): The download file is named: "MacOSXUpdate10.2.5.dmg". For G5s only.

Note that there is a specific standalone updater for the Power Mac G5.

[Update 9a EDT 10/4] Security Updates in Mac OS X 10.2.8: Mac OS X 10.2.8 contains security enhancements for the following:

OpenSSL: Fixes CAN-2003-0543, CAN-2003-0544, CAN-2003-0545 to address potential issues in certain ASN.1 structures and in certificate verification code. To deliver the update in a rapid and reliable manner, only the patches for the CVE IDs listed above were applied, and not the entire latest OpenSSL library. Thus, th OpenSSL version in Mac OS X 10.2.8, as obtained via the "openssl version" command, is: OpenSSL 0.9.6i Feb 19 2003

OpenSSH: Mac OS X 10.2.8 contains the patches to address CVE CAN-2003-0693, CAN-2003-0695, and CAN-2003-0682. On Mac OS X versions prior to 10.2.8, the vulnerability is limited to a denial of service from the possibility of causing sshd to crash. Each login session has its own sshd, so established connections are preserved up to the point where system resources are exhausted by an attack. To deliver the update in a rapid and reliable manner, only the patches for CVE IDs listed above were applied, and not the entire set of patches for OpenSSH 3.7.1. Thus, the OpenSSH version in Mac OS X 10.2.8, as obtained via the "ssh -V" command, is: OpenSSH_3.4p1+CAN-2003-0693, SSH protocols 1.5/2.0, OpenSSL 0x0090609f

fb_realpath(): Fixes CAN-2003-0466 which is an off-by-one error in the fb_realpath() function that may allow attackers to execute arbitrary code.

arplookup(): Fixes CAN-2003-0804. The arplookup() function caches ARP requests for routes on a local link. On a local subnet only, it is possible for an attacker to send a sufficient number of spoofed ARP requests which will exhaust kernel memory, leading to a denial of service.

Sendmail: Addresses CVE CAN-2003-0694 and CAN-2003-0681 to fix a buffer overflow in address parsing, as well as a potential buffer overflow in ruleset parsing.

Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Software · This month in the archive