MacMegasite Archive
   


To reduce the database size and server load, all articles from 2004 or earlier are archived here.


Return to MacMegasite



       

Thu, 19 Dec 2002

Apple Security Alert 2002-12-19 Mac OS X 10.2.3

Apple has documented several security issues that have been fixed in Mac OS X 10.2.3, which is now available in the Software Update control panel.



  • fetchmail: Fixes CAN-2002-1174 and CAN-2002-1175 which could lead

    to a potential denial of service when using the fetchmail command-line tool.

    fetchmail is updated to version 6.1.2+IMAP-GSS+SSL+INET6



  • CUPS: Provides fixes for the following potential issues that could be

    exploited remotely when Printer Sharing is enabled. Printer Sharing is

    not enabled by default on Mac OS X or Mac OS X Server.



    CAN-2002-1383: Multiple Integer Overflows

    CAN-2002-1366: /etc/cups/certs/ Race Condition

    CAN-2002-1367: Adding Printers with UDP Packets

    CAN-2002-1368: Negative Length Memcpy() Calls

    CAN-2002-1384: Integer Overflows in pdftops Filter and Xpdf

    CAN-2002-1369: Unsafe Strncat Function Call in jobs.c

    CAN-2002-1370: Root Certificate Design Flaw

    CAN-2002-1371: Zero Width Images in filters/image-gif.c

    CAN-2002-1372: File Descriptor Resource Leaks





In addition, Mac OS X 10.2.3 provides the following enhanced security features:



  • Random initialization of TCP Timestamp: This enhancement was submitted by

    Aaron Linville through the Darwin open source program. It prevents a remote entity

    from discovering how long a machine has been up based on the ID in the TCP packets.



  • Disk Utility now provides the option to zero data on the disk, providing an

    additional method for securing information.





Mac OS X 10.2.3 Software Update may be obtained from:



  • Software Update pane in System Preferences



    - OR -



  • Apple's Software Downloads web site:


    Updating from Mac OS X 10.2:


    http://www.info.apple.com/kbnum/n120164


    The download file is named: "MacOSXUpdateCombo10.2.3.dmg"


    Its SHA-1 digest is: 46df611279b9981425be2cff23c3b3ed868d1809



    Updating from Mac OS X 10.2.2:

    http://www.info.apple.com/kbnum/n120165


    The download file is named: "MacOSXUpdate10.2.3.dmg"


    Its SHA-1 digest is: a51ed65311ad59879db7e728779e9cd4084057b5



Information will also be posted to the Apple Support web site:

http://docs.info.apple.com/article.html?artnum=61798



[] permanent link

Mac OS X 10.2.3 Update Available

Apple has released the Mac OS X 10.2.3 update, now available via the Software Update control panel.

The 10.2.3 Update delivers enhanced functionality and improved reliability for the following applications, utilities, and technologies: AppleScript, Classic compatibility, Disk Copy, Disk Utility, Image Capture, Mail, OpenGL, Print Center, and Rendezvous. It provides audio, disc recording, graphics, printing improvements, as well as AFP and WebDAV networking improvements. The update also provides updated security services and includes the latest Security Updates.



For detailed information on this Update, please visit http://www.info.apple.com/kbnum/n107263.

[] permanent link

A-OK! The Wings of Mercury 3.0.2 Now On Mac OS X!

December 19, 2002. Brick, NJ - YOU ARE GO! has released A-OK! The Wings of Mercury 3.0.2 for Mac OS X. A free upgrade for the Mac OS 9 version has also been released. These versions incorporate some improvements in cloud rendering and reduce mission start up time by 95%. The Mac OS X version supports 3D HID-compatible joysticks.



A-OK! The Wings of Mercury is priced at $59.95 and $29.95 for an upgrade from 2.x. A demo version, which can be upgraded to a full version right from the program, is available for download at the A-OK! WoM web site. (www.aokwom.com) The Windows version is now in development.



A-OK! WoM Merchandise


Visitors to www.aokwom.com can visit the A-OK! WoM Store and buy A-OK! WoM gear such as T-shirts, mugs and license plate frames. More items will be added early 2003.



Background


A-OK! The Wings of Mercury simulates America's first spacecraft, Project Mercury, and opens a new frontier in computer simulations. The operation of every gauge, light and switch in the spacecraft is simulated to a high degree of fidelity. So accurate are the spacecraft systems that users consult reproductions of the actual flight documentation used by the Mercury astronauts. The simulator can generate hundreds of failure scenarios that require split-second decisions to survive.



A-OK! The Wings of Mercury ships with A-OK! Mission Control Center, an application that simulates the consoles at Mercury mission control.



A-OK! The Wings of Mercury also ships with a suite of tools that allows users to edit the launch and landing areas, calculate retrofire and ground station contact times and other mission-critical tasks.



The demo version is restricted to sub-orbitial, non-networked simulations and does not allow the use of the A-OK! Tool Kit. In addition, to removing these restrictions, registered users will be entitled to free updates from version 3.0 to 3.9 and priority in bug reporting and follow-up.



YOU ARE GO! is a division of Pyramid Design, a software development firm, based in New Jersey. In addition to A-OK! WoM, Pyramid Design is a software development contracting and consulting firm.

[] permanent link