Brief Hands-On Report--Mac OS X 10.3.9 Client and Server

Last night Apple released Mac OS X 10.3.9 update for client and server. They are available for download via the System Preference Software Update pane and as standalone updaters, either as a delta version (client and server, 10.3.8 to 10.3.9) or as a combo version (client and server, 10.3.x to 10.3.9). We recommend the combo version to minimize the chance of any problems.

Here is what Apple says is in the delta updaters, i.e. new for 10.3.9:

Client (Delta) Improvements include:

  • file sharing and directory services reliability for mixed Mac and PC networks
  • Mail, Safari and Stickies application reliability
  • compatibility for third party applications and devices
  • previous standalone security updates
  • Server (Delta) Improvements include:
  • reliability of Open Directory authentication requests, and Active Directory integration
  • AFP performance when listing large files and directories
  • update to Cyrus version 2.2.10 for more reliable email message storage
  • reliability of Ethernet communications on Xserve
  • compatibility for third party applications and devices
  • previous standalone security updates

Server (Delta) Improvements include:

  • reliability of Open Directory authentication requests, and Active Directory integration
  • AFP performance when listing large files and directories
  • update to Cyrus version 2.2.10 for more reliable email message storage
  • reliability of Ethernet communications on Xserve
  • compatibility for third party applications and devices
  • previous standalone security updates

Here are the details on the security aspects:

Kernel

CVE ID: CAN-2005-0969
Impact: A kernel input validation issue can lead to a local denial of service
Description: The Kernel contains syscall emulation functionality that was never used in Mac OS X. Insufficient validation of an input parameter list could result in a heap overflow and a local denial of service through a kernel panic. The issue is addressed by removing the syscall emulation functionality. Credit to Dino Dai Zovi for reporting this issue.

CVE ID: CAN-2005-0970
Impact: Permitting SUID/SGID scripts to be installed could lead to privilege escalation.
Description: Mac OS X inherited the ability to run SUID/SGID scripts from FreeBSD. Apple does not distribute any SUID/SGID scripts, but the system would allow them to be installed or created. This update removes the ability of Mac OS X to run SUID/SGID scripts. Credit to Bruce Murphy of rattus.net and Justin Walker for reporting this issue.

CVE ID: CAN-2005-0971
CERT: VU#212190
Impact: A Kernel stack overflow in the semop() system call could lead to a local privilege escalation.
Description: The incorrect handling of system call arguments could be used to obtain elevated privileges. This update includes a fix to check access to the kernel object.

CVE ID: CAN-2005-0972
CERT: VU#185702
Impact: An integer overflow in the searchfs() system call could allow an unprivileged local user to execute arbitrary code with elevated privileges
Description: The searchfs() system call contains an integer overflow vulnerability that could allow an unprivileged local user to execute arbitrary code with elevated privileges. This update adds input validation on the parameters passed to searchfs() to correct the issue.

CVE ID: CAN-2005-0973
Impact: Local system users can cause a system resource starvation
Description: A vulnerability in the handling of values passed to the setsockopt() call could allow unprivileged local users to exhaust available memory. Credit to Robert Stump <rds3792@cs.rit.com> for reporting this issue.

CVE ID: CAN-2005-0974
CERT: VU#713614
Impact: Local system users can cause a local denial of service
Description: A vulnerability in the nfs_mount() call due to insufficient checks on input values could allow unprivileged local users to create a denial of service via a kernel panic.

CVE ID: CAN-2005-0975
Impact: Local system users can cause a temporary interruption of
system operation
Description: A vulnerability in the parsing of certain executable files could allow unprivileged local users to temporarily suspend system operations. Credit to Neil Archibald for reporting this issue.

Safari

CVE ID: CAN-2005-0976
Impact: Remote sites could cause html and javascript to run in the local domain.
Description: This update closes a vulnerability that allowed remote websites to load javascript to execute in the local domain. Credit to David Remahl for reporting this issue.

We downloaded and installed the client and server editions (combo versions) on a number of Macs, including several PowerBooks. No problems were encountered while updating or while briefly using the new version. The only thing we noticed is that sleep on our PowerBook seems to be improved. Note in the server read me file that there are a number of things that should be done for certain configurations.

We updated with our backup FireWire drive attached to our 17" PowerBook with no apparent problems and it still booted our PowerBooks with 10.3.8 after the update. But it became unbootable after it was updated to 10.3.9. We will proba have to use Carbon Copy Cloner again to restore the backup drive to bootable condition as we had to do with 10.3.8.

Safari seems to load pages faster but that may be due to our internet connection being really good right now. But there doesn't seem to be any hesitation in loading pages as before. Unfortunately, Safari on our 17" PowerBook now quits unexpectedly very frequently [Update: This was fixed by deleting Safari's preference file and relaunching. We did not have this minor problem on any other Mac or 'Book]. [Bill Fox & Dana Baggett]



Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Reviews · This month in the archive