Brief Hands-On Report--Apple Security Update 2004-05-03 for Mac OS X

Security Update 2004-05-03 is available via the Software Update preference pane or as a standalone updater. It is available for both Mac OS X 10.3.3 and Mac OS X 10.2.8 and client and server editions.

According to the Read Me file, Security Update 2004-05-03 delivers a number of security enhancements and is recommended for all Macintosh users. This update includes the following components for the OS X client:

AFP Server
CoreFoundation
IPSec

Additionally, Security Update 2004-04-05 has been incorporated into this security update. Those components are:

CUPS Printing
libxml2
Mail
OpenSSL

and in addition for Mac OS X Server:

Apache 2

Here are the details:

CoreFoundation: Fixes CAN-2004-0428 to improve the handling of an
environment variable. Credit to aaron@vtty.com for reporting this
issue.

Apache 2: Fixes CAN-2003-0020, CAN-2004-0113 and CAN-2004-0174 by
updating to Apache 2 to version 2.0.49.

RAdmin: Fixes CAN-2004-0429 to improve the handling of large requests

AppleFileServer: Fixes CAN-2004-0430 to improve the handling of long
passwords. Credit to Dave G. from @stake for reporting this issue.

IPSec: Fixes CAN-2004-0155 and CAN-2004-0403 to improve the security
of VPN tunnels. IPSec in Mac OS X is not vulnerable to
CAN-2004-0392.

We downloaded and installed the client and server editions for Mac OS X 10.3.3 on a Power Mac G45, G4 Cubes, PowerBook G4s and an iBook G3 with no apparent problems.

Saw something? Send a tip or a correction

The archive ran on reader tips. What did you see, where, and do you want the credit? Something wrong on this page? Say so and it gets fixed.

Read by the editor. You get a copy by email. Never published without your say.

More in Security · This month in the archive