Apple Updated Xcode to v2.3 for Developers
It fixes the following security issue:
WebObjects CVE-2006-1466 -- The WebObjects Xcode plug-in provides the ability to manipulate projects through a network service. This service is accessible to remote systems while Xcode is running. This update addresses the issue by limiting this service to the local system. This issue does not affect default installations of Xcode Tools. Only systems with the WebObjects plug-in installed are affected. Credit to Mike Schrag of mDimension Technology for reporting this issue.Impact: If you install WebObjects developer tools, remote
attackers may be able to obtain or modify WebObjects projects
while Xcode is running
[Bill Fox]
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?