Brief Hands-On Report--AirPort Extreme Update 2007-001

AirPort Extreme Update 2007-001 is available via Software Update or as a stand-alone file from this Apple Web page.

According to Apple,

This update is recommended for all Intel-based Macintosh computers and provides compatibility with AirPort Extreme base stations and networks.

Here are the security details:

AirPort
CVE-ID: CVE-2006-6292
Available for: Mac OS X v10.4.8, Mac OS X Server v10.4.8
Impact: Attackers on the wireless network may cause system
crashes
Description: An out-of-bounds memory read may occur while
handling wireless frames. An attacker in local proximity may be
able to trigger a system crash by sending a maliciously-crafted
frame to an affected system. This issue affects the Core Duo
version of Mac mini, MacBook, and MacBook Pro computers equipped
with wireless. Other systems, including the Core 2 Duo versions
are not affected. This update addresses the issue by performing
additional validation of wireless frames. Credit to LMH for
reporting this issue.

We downloaded the update and installed it on a MacBook Pro Core 2 Duo and an iMac Core Duo with no difficulty. Our brief use before publication time did not reveal any problems. [Bill Fox & Dana Baggett]

Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Reviews · This month in the archive