Details on the Apple Mac OS X 10.4.1 Server Update

Mac OS X 10.4.1 Seerver Update is available for download either from the System Preferences Software Update pane or as a standalone updater from this Apple Web page. According to Apple,

The 10.4.1 Server Update delivers overall improved reliability for Mac OS X Server v10.4 and is recommended for all systems.

It includes improvements for:

-file sharing using AFP and SMB/CIFS network file services
-Software Update Server notifications and synchronization of package downloads
-displaying published Weblog Server content after a reboot
-binding to LDAP and Active Directory during system startup
-remote management using the Server Admin application
-creating and burning disk images using Disk Utility and System Image Utility
-compatibility with third party applications and devices

Here are the details of some of the enhancements and improvements:

Software Update Server

• Addresses an issue where the Software Update Service may not automatically download and host mirrored updates.

Open Directory

• Addresses an issue in which users may not be able to add Password Hints to an Access Control List.
• Addresses an issue in which static LDAP binding entries may be lost when bound to a DNS entry which resolves to many IP addresses.
• Addresses startup issues which may prevent computers from fully starting up when bound via Active Directory and hosting multiple services.

Apple File Server

• Addresses an issue in which the Apple File Server may stop unexpectedly when used simultaneously with SMB and CIFS.
servermgrd
• Addresses an issue that may cause the servermgrd service to stop unexpectedly over time with multiple services running.
Weblogs
• Addresses an issue in which user Weblogs may appear to be unavailable, even though they're really still available.
Mail Services
• Addresses mail migration issues in which the mail databases may be located on a different partition separate from where the 10.4.1 install resides. Additional mail database reconstruct instructions may be found here.

Disk Imaging

• Addresses an issue in which Disk Images may not properly uncompress and mount when stored on an Automounted Home Directory

Here are the security enhancements for both 10.4.1 Client and Server:

Bluetooth

CVE-ID: CAN-2005-1333
Available for: Mac OS X v10.4, Mac OS X Server v10.4
Impact: Directory traversal via Bluetooth file and object exchange
Description: Due to insufficient input checking, the Bluetooth file and object exchange services could be used to access files outside of the default file exchange directory. This update addresses the issue by adding enhanced filtering for path-delimiting characters. Credit to kf_lists[at]digitalmunition[dot]com for reporting this issue.

Dashboard

CVE-ID: CAN-2005-1474
Available for: Mac OS X v10.4, Mac OS X Server v10.4
Impact: Malicious websites can download and install widgets via Safari without the Safe Download Validation warning
Description: This update blocks the automatic installation of Dashboard widgets. Mac OS X's Safe Download Validation warning is enabled, requiring user approval before a Dashboard widget is installed by Safari. This issue does not affect Mac OS X versions prior to 10.4. Further information on removing Dashboard widgets that you have installed is available from this article.

Kernel

CVE-ID: CAN-2005-1472
Available for: Mac OS X v10.4, Mac OS X Server v10.4
Impact: Users can discover the names of files placed in normally unsearchable places
Description: Two system calls designed to allow efficient searching of filesystem objects incorrectly checked the permissions on enclosing directories and would reveal the names of files. The incorrect checking only occurred for directories without the POSIX read, but with the POSIX execute bits set for group and other. In practice this issue only affects files stored in users ~/Public/Drop Box. This update addresses the issue by correctly honoring the POSIX permission bits on directories. Credit to John M. Glenn of San Francisco for reporting this issue.

CVE ID: CAN-2005-0974 CERT: VU#713614
Available for: Mac OS X v10.4, Mac OS X Server v10.4
Impact: Local system users can cause a local denial of service
Description: A vulnerability in the nfs_mount() call due to insufficient checks on input values could allow unprivileged local users to create a denial of service via a kernel panic.

SecurityAgent

CVE-ID: CAN-2005-1473
Available for: Mac OS X v10.4, Mac OS X Server v10.4
Impact: Users with physical access to a system with a locked screensaver can start background applications
Description: A contextual menu feature in Mac OS X 10.4 allows URLs to be opened from a text input field. This could be used to launch an application behind a locked screensaver window. This update addresses the issue by removing the contextual menu from screensaver text input fields.

[Bill Fox]



Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Mac OS · This month in the archive