Brief Hands-On Report--AirPort Extreme Update 2007-001
According to Apple,
This update is recommended for all Intel-based Macintosh computers and provides compatibility with AirPort Extreme base stations and networks.
Here are the security details:
AirPort
CVE-ID: CVE-2006-6292
Available for: Mac OS X v10.4.8, Mac OS X Server v10.4.8
Impact: Attackers on the wireless network may cause system
crashes
Description: An out-of-bounds memory read may occur while
handling wireless frames. An attacker in local proximity may be
able to trigger a system crash by sending a maliciously-crafted
frame to an affected system. This issue affects the Core Duo
version of Mac mini, MacBook, and MacBook Pro computers equipped
with wireless. Other systems, including the Core 2 Duo versions
are not affected. This update addresses the issue by performing
additional validation of wireless frames. Credit to LMH for
reporting this issue.
We downloaded the update and installed it on a MacBook Pro Core 2 Duo and an iMac Core Duo with no difficulty. Our brief use before publication time did not reveal any problems. [Bill Fox & Dana Baggett]
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?