Details on Security Update in AirPort 4.2

Apple updated its AirPort software to v4.2 last week as we reported on 7/15. Included is a security update. Here are the details:

Available for: Mac OS X 10.3.3 to 10.3.9 & 10.4.2
CVE-ID: CAN-2005-2196
Impact: Mobile users with the original AirPort card enabled could automatically associate to an malicious network
Description: When not connected to a known or trusted network, the AirPort card "parks" on a randomly generated network with a default WEP key. This can allow parked AirPort cards to automatically connect to malicious networks without warning. This condition only applies to AirPort cards and does not affect AirPort Extreme. The System Profiler utility can be used to indicate the type of AirPort card installed. This update addresses the problem by using a randomly-generated 128-bit WEP key instead of the default WEP key. Credit to Dino Dai Zovi for reporting this issue.

[Bill Fox]



Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Security · This month in the archive