Apple Updated its Xsan Software to v1.4
Xsan Admin 1.4 Update--The Xsan 1.4 update delivers overall improved reliability for remotely administering, configuring and maintaining Xsan deployments. It includes fixes for:
- labeling and initializing Fibre Channel LUNs larger than 2TB in size
- expanding storage pools and volumes
- working with multiple Xsan metadata controllers in a heterogeneous environment
- displaying progress messages while performing lengthy operations
- preventing custom configuration changes from being overwritten during a save
- accurately reporting Fibre Channel multipathing errors
Xsan Filesystem 1.4 for Mac OS X 10.4--The Xsan 1.4 update improves reliability and is recommended for all systems running Mac OS X or Mac OS X Server version 10.4. It includes fixes for:
- using file system access control lists (ACLs)
- labeling and initializing LUNs greater than 2TB in size
- AFP and NFS performance when re-sharing Xsan volumes
- handling file system quotas and notifications
- compatibility with Apple and third party applications
It also fixes this security issue:
CVE-ID: CVE-2006-3506
Available for: Mac OS X v10.4.7, Mac OS X Server v10.4.7
Impact: Malicious users may be able to cause systems using Xsan
to crash or execute arbitrary code
Description: A buffer overflow may occur in the Xsan Filesystem
driver when processing a path name. A malicious user with write
access to an Xsan volume may be able to trigger the overflow on
systems directly attached to Xsan. This could lead to a system
crash or arbitrary code execution with system privileges. This
update addresses the issue by performing additional validation
of path names. Credit to Andrew Wellington of The Australian
National University for reporting this issue.
[Bill Fox]
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?