This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Apple Mac Os X Security Update 2007-004

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

Security Update 2007-004
- http://docs.info.apple.com/article.html?artnum=305391
04/19/2007

- http://isc.sans.org/diary.html?storyid=2665
Last Updated: 2007-04-19 20:42:32 UTC ~ "Apple Computers released an update which addresses a number of security issues in the Mac OS X and OS X Server systems… There are about 25 separate vulnerabilities that are addressed which range from remote attackers causing denial of service attacks all the way to local users having some form of escalation of privileges… The updates can be applied via the Software Update icon* in the apple menu, or downloading and installing the appropriate update available from Apple Support Downloads site**."

* http://docs.info.apple.com/article.html?artnum=106704

** http://www.apple.com/support/downloads/

- http://secunia.com/advisories/24966/
Release Date: 2007-04-20
Critical: Highly critical

.
FYI…

APPLE-SA-2007-05-01 Security Update 2007-004 -v1.1-
- http://isc.sans.org/diary.html?storyid=2726
Last Updated: 2007-05-02 02:27:44 UTC ~ "In addition to the Quicktime patches, Apple also released APPLE-SA-2007-05-01 Security Update 2007-004 v1.1 which contains the following:
Security Update 2007-004 v1.1 includes the contents of Security Update 2007-004, plus the following fixes:
AirPort
Available for: Mac OS X v10.3.9
This update corrects an issue where the AirPort connection may be lost after waking from sleep. This issue only affects Mac OS X v10.3.9 with Security Update 2007-004.
FTPServer
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0745
Available for: Mac OS X Server v10.4.9
Impact: Users with ftp access may be able to navigate to directories outside the normal scope
>>> Description: Security Update 2007-004 applied an incorrect ftp configuration file for Mac OS X Server v10.4.9 systems. Users with ftp access, who would normally be restricted to certain directories, may be able to access directories outside the normal scope. This update addresses the issue by restoring the correct version of the ftp configuration file. This issue only affects Mac OS X Server v10.4.9 with Security Update 2007-004.
Mac OS X 10.4.9 (client) and Mac OS X Server 10.3.9 systems that have installed Security Update 2007-004 do not require Security Update 2007-004 v1.1. If the security update has not yet been installed on these systems, then they should be updated using Security Update 2007-004 v1.1.
Security Update 2007-004 v1.1 may be obtained from the Software Update pane in System Preferences, or Apple's Software Downloads website:
http://www.apple.com/support/downloads/ …
Original announcement http://docs.info.apple.com/article.html?artnum=61798 "

- http://secunia.com/advisories/24966
Last Update: 2007-05-02
Critical: Highly critical

:ph34r:
FYI…

Update on Apple fix
- http://isc.sans.org/diary.html?storyid=2736
Last Updated: 2007-05-03 21:09:15 UTC
"…From: http://docs.info.apple.com/article.html?artnum=305445
Update:
If you are running OSX Server 10.4.9, it is critical to apply the new 2007-004 v.1.1 as mentioned in the above Apple doc:
"Description: Security Update 2007-004 applied an incorrect ftp configuration file for Mac OS X Server v10.4.9 systems. Users with ftp access, who would normally be restricted to certain directories, may be able to access directories outside the normal scope. This update addresses the issue by restoring the correct version of the ftp configuration file. This issue only affects Mac OS X Server v10.4.9 with Security Update 2007-004…"

.