Details on Security Update in AirPort 4.2
Available for: Mac OS X 10.3.3 to 10.3.9 & 10.4.2
CVE-ID: CAN-2005-2196
Impact: Mobile users with the original AirPort card enabled could automatically associate to an malicious network
Description: When not connected to a known or trusted network, the AirPort card "parks" on a randomly generated network with a default WEP key. This can allow parked AirPort cards to automatically connect to malicious networks without warning. This condition only applies to AirPort cards and does not affect AirPort Extreme. The System Profiler utility can be used to indicate the type of AirPort card installed. This update addresses the problem by using a randomly-generated 128-bit WEP key instead of the default WEP key. Credit to Dino Dai Zovi for reporting this issue.
[Bill Fox]
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?