Brief Hands-On Report--Apple released Mac OS X 10.4.8 for Client and Server

Apple released Mac OS X 10.4.8 Update for client and Server editions, for PowerPC- and Intel-based Macs and as delta and combo updaters. The appropriate delta or combo updater should appear in Software Update and there are stand-alone updaters available for download from this Apple Web page. Generally, we recommend that people download the stand-alone combo updater and use it to update to Mac OS X 10.4.8, particularly if one has not been judicious in keeping Mac OS X up to date or is having problems. For others, the shorter route is using Software Update--we did. But we also downloaded the combo updater to keep in case of future problems.

Mac OS X 10.4.8 is a significant update with new versions of applications and utilities: Address Book, AppleScript, Automator, Dictionary, Font Book, iCal, iChat, DVD Player, Keynote, Mail, Preview, Safari, Stickies, Disk Utility, Keychain Access, Migration Assistant, and Software Update.

Here the details of the major client changes (PowerPC and Intel):

The 10.4.8 Update is recommended for all users and includes general operating system fixes, as well as specific fixes for the following applications and technologies:

- sharing using AFP, SMB/CIFS, NFS and FTP file sharing protocols
- reliable access to Open Directory, LDAP and Active Directory services
- login and authentication in a variety of network environments
- file access and byte range locking with AFP file sharing
- network access when using proxy server automatic configuration files
- connecting to Cisco VPN servers using IP/Sec and NAT
- AirPort including connectivity to EAP-FAST networks
- Bluetooth wireless connectivity
- RAW camera support, including updated ATI and NVIDIA graphics drivers
- usability of Dashboard and widgets
- searching iWork ‘06 and Microsoft Office documents with Spotlight
- saving Word documents automatically when using a network home directory
- viewing of QuickTime streaming media behind a firewall
- audio playback in QuickTime, iTunes, Final Cut Pro, and Soundtrack applications
- ensuring icons are spaced correctly when viewed on desktop
- determining the space required to burn folders
- synchronizing contacts, bookmarks, and calendars to .Mac and mobile phones
- mounting and unmounting iDisk volumes
- time zone and daylight savings for 2006 and 2007
- using OpenType fonts in Microsoft Word
- Address Book, AppleScript, Automator, Dictionary, Font Book, iCal, iChat, DVD Player, Keynote, Mail, Preview, Safari, and Stickies
- Disk Utility, Keychain Access, Migration Assistant, and Software Update
- compatibility with third party applications and devices
- previous Mac OS X updates and standalone security updates

Here are the details of the PowerPC-based Server changes:

- avoiding AFP server deadlocks and thread starvation
- membership and permissions issues when Windows users are in more than 16 groups
- synchronizing Open Directory password information between Master and Replicas
- changing and saving Open Directory password policy security settings
- directory service usage affecting Mail server performance
- streaming movies to localized versions of the QuickTime Player
- handling TCP Selective Acknowledgments in congested networks
- compatibility with third party applications and devices
- previous standalone security updates

Here are the Intel-based Server details:

- avoiding AFP server deadlocks and thread starvation
- streaming movies to localized versions of the QuickTime Player
- preventing panics when operating with Xsan and other memory intensive kernel extensions
- vnode allocation on systems with at least 2GB of RAM
- handling TCP Selective Acknowledgments in congested networks
- compatibility with third party applications and devices
- previous standalone security updates

Here are the details of the twelve security updates included with Mac OS X 10.4.8:

CFNetwork--CVE-2006-4390--CFNetwork clients such as Safari may allow unauthenticated SSL sites to appear as authenticated. This update addresses the issue by disallowing anonymous SSL connections by default. Credit to Adam Bryzak of Queensland University of Technology for reporting this issue.

Flash Player--CVE-2006-3311, CVE-2006-3587, CVE-2006-3588, CVE-2006-4640--Playing Flash content may lead to arbitrary code execution. This update addresses the issues by incorporating Flash Player version 9.0.16.0 on Mac OS X v10.3.9 and Flash Player version 9.0.20.0 on Mac OS X v10.4.

ImageIO--CVE-2006-4391--Viewing a maliciously-crafted JPEG2000 image may lead to an application crash or arbitrary code execution. This update addresses the image by performing additional validation of JPEG2000 images. This issue does not affect systems prior to Mac OS X v10.4. Credit to Tom Saxton of Idle Loop Software Design for reporting this issue.

Kernel--CVE-2006-4392--Local users may be able to run arbitrary code with raised privileges. This update addresses the issue by restricting access to Mach exception ports for privileged programs. Credit to Dino Dai Zovi of Matasano Security for reporting this issue.

LoginWindow--CVE-2006-4397--fter an unsuccessful attempt to log in to a network account, Kerberos tickets may be accessible to other local users. This update addresses the issue by clearing the credentials cache after failed logins. This issue does not affect systems prior to Mac OS X v10.4. Credit to Patrick Gallagher of Digital Peaks Corporation for reporting this issue.

LoginWindow--CVE-2006-4393--Kerberos tickets may be accessible to other local users if Fast User Switching is enabled. Fast User Switching has been updated toprevent this situation. This issue does not affect systems prior to Mac OS X v10.4. Credit to Ragnar Sundblad of the Royal Institute of Technology, Stockholm, Sweden for reporting this issue.

LoginWindow--CVE-2006-4394--Network accounts may be able to bypass loginwindow service access controls. This issue only affects systems that have been configured to use service access controls for loginwindow and to allow network accounts to authenticate users without a GUID. The issue has been resolved by properly handling service access controls in loginwindow. This issue does not affect systems prior to Mac OS X v10.4.

Preferences--CVE-2006-4387--After removing an account's Admin privileges, the account may still manage WebObjects applications. This update addresses the issue by ensuring the account is removed from the appropriate groups. This issue does not affect systems prior to Mac OS X v10.4. Credit to Phillip Tejada of Fruit Bat Software for reporting this issue.

QuickDraw Manager--CVE-2006-4395--Opening a malicious PICT image with certain applications may lead to an application crash or arbitrary code execution. This update addresses the issue by preventing the unsupported operation.

SASL--CVE-2006-1721--Remote attackers may be able to cause an IMAP server denial of service. This update addresses the issue through improved handling of realm heders in authentication attempts.

WebCore--CVE-2006-3946--Viewing a maliciously-crafted web page may lead to arbitrary code execution. This update addresses the issue by preventing the condition causing the overflow. Credit to Jens Kutilek of Netzallee for reporting this issue.

Workgroup Manager--CVE-2006-4399--Accounts in a NetInfo parent that appear to use ShadowHash passwords may still use crypt. This update addresses the issue by disallowing administrators from selecting ShadowHash passwords for accounts in a NetInfo parent. Credit to Chris Pepper of The Rockefeller University for reporting this issue.

We downloaded and installed Mac OS X 10.4.8 client and Server on a number of Macs, mostly using Software Update: Mac mini Core Duo, iMac Core Duo, iMac Core 2 Duo, 15" MacBook Pro, PowerBook G4 and Power Mac G4 Cube. It took quite awhile for the Macs to restart following installation. In addition, a very long time was spent at the gray screen after the restart and most, if not all, Macs restarted again before proceeding to the desktop. We experienced no problems with installation on any Mac.

Afterward, several hours of use of many of the updated Macs, Power PC and Intel, revealed no problems. The Apple Mail application that had slowed down considerably after being installed with 10.4.7 was much faster at accessing the mailboxes after the 10.4.8 update. [Bill Fox and Dana Baggett].

Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Reviews · This month in the archive