Reply to topic  [ 6 posts ] 
Critical flaw forces Apple to push automatic update 
Author Message
Legend

Joined: Sun Apr 26, 2009 12:30 pm
Posts: 45931
Location: Belfast
Reply with quote
http://www.techradar.com/news/security- ... er-1278217

_________________
Plain English advice on everything money, purchase and service related:

http://www.moneysavingexpert.com/


Tue Dec 23, 2014 3:48 pm
Profile
Doesn't have much of a life
User avatar

Joined: Fri Apr 24, 2009 12:43 pm
Posts: 1798
Location: Manchester
Reply with quote
This popped up in the App Store on my Mavericks 10.9 Macbook and iMac, except it wasn't an automatic update, completely optional if you so wished - so that part of the article is complete bollox. Still, they never let the truth get in the way of a good story.

_________________
* Steve *

* Witty statement goes here *


Tue Dec 23, 2014 11:11 pm
Profile
What's a life?
User avatar

Joined: Thu Apr 23, 2009 7:26 pm
Posts: 17040
Reply with quote
Nope. I have two macs. One of them it showed up in software update and I installed it the same way any update would be. The other, I went back to it after a day away and there was a notification saying it had already been installed. I didn't click a thing.

I don't really mind security updates being applied automatically but it does make me wonder exactly what was broken in their NTP client that required a patch of such urgency.

Jon


Wed Dec 24, 2014 12:26 am
Profile
What's a life?
User avatar

Joined: Thu Apr 23, 2009 8:25 pm
Posts: 10691
Location: Bramsche
Reply with quote
Buffer overflow or similar. The NTP service runs with relatively high privileges anyway, as it needs to change the system time. The bug allowed an exploit, which allowed attackers to gain remote control over the affected Mac.

_________________
"Do you know what this is? Hmm? No, I can see you do not. You have that vacant look in your eyes, which says hold my head to your ear, you will hear the sea!" - Londo Molari

Executive Producer No Agenda Show 246


Wed Dec 24, 2014 8:57 am
Profile ICQ
What's a life?
User avatar

Joined: Thu Apr 23, 2009 7:26 pm
Posts: 17040
Reply with quote
Docs say it's this one - CVE-2014-9295.
Would it be wise to assume other Unix systems running NTP < 4.2.7 are also vulnerable?


Last edited by jonbwfc on Wed Dec 24, 2014 3:10 pm, edited 1 time in total.



Wed Dec 24, 2014 10:18 am
Profile
What's a life?
User avatar

Joined: Thu Apr 23, 2009 8:25 pm
Posts: 10691
Location: Bramsche
Reply with quote
That is the one. It has been addressed in most Linux distributions already, by the look of it.

_________________
"Do you know what this is? Hmm? No, I can see you do not. You have that vacant look in your eyes, which says hold my head to your ear, you will hear the sea!" - Londo Molari

Executive Producer No Agenda Show 246


Wed Dec 24, 2014 12:21 pm
Profile ICQ
Display posts from previous:  Sort by  
Reply to topic   [ 6 posts ] 

Who is online

Users browsing this forum: No registered users and 5 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group
Designed by ST Software.