erbic Posted February 15, 2007 Share Posted February 15, 2007 (edited) Well, Apple's released another Security Update. This one contains fixes for CoreServices (specifically the Finder), iChat, and the UserNotification Center. They credited the MOAB guys for finding the bug in Finder. Finder CVE-ID: CVE-2007-0197 Available for: Mac OS X v10.4.8, Mac OS X Server v10.4.8 Impact: Mounting a maliciously-crafted disk image may lead to an application crash or arbitrary code execution Description: A buffer overflow exists in Finder's handling of volume names. By enticing a user to mount a malicious disk image, an attacker could trigger this issue, which may lead to an application crash or arbitrary code execution. A proof of concept for this issue has been published on the "Month of Apple Bugs" website (MOAB-09-01-2007). This update addresses the issue by performing additional validation of disk images. This issue does not affect systems prior to Mac OS X v10.4. Credit to Kevin Finisterre of DigitalMunition for reporting this issue. Linky. I have no idea if this one could break Hackintoshes. Someone more technical should test it out. EDIT: Fixed the quote. It formatted itself weird when I pasted it in. Edited February 15, 2007 by ErBiC Link to comment https://www.insanelymac.com/forum/topic/42533-security-update-2007-002-is-out/ Share on other sites More sharing options...
macgirl Posted February 15, 2007 Share Posted February 15, 2007 I shouldn't try on Hackintoshes. There are also: Java for Mac OS X 10.4 Release 5 This update adds support for the latest Daylight Saving Time (DST) and time zone information as of January 8, 2007 and delivers improved reliability and compatibility for Java 2 Platform Standard Edition 5.0 and Java 1.4. Daylight Saving Time Update (Tiger) This update addresses recent changes in the way Daylight Saving Time will be observed in the U.S. and Canada beginning in March 2007 and includes the latest time zone information for the rest of the world. WebObjects 5.3.3 This installer updates WebObjects 5.3 systems to observe the Daylight Saving Time (DST) and 2007 time zone changes as of January 8, 2007. Link to comment https://www.insanelymac.com/forum/topic/42533-security-update-2007-002-is-out/#findComment-304121 Share on other sites More sharing options...
mifki Posted February 15, 2007 Share Posted February 15, 2007 Hmm, this wont work on amd yet, someone needs to decrypt it and cpuid patch it Link to comment https://www.insanelymac.com/forum/topic/42533-security-update-2007-002-is-out/#findComment-304124 Share on other sites More sharing options...
erbic Posted February 16, 2007 Author Share Posted February 16, 2007 I don't think the CoreServices update would break a Hackintosh. All it does (supposedly) is add some more DMG checking in Finder. I might wonder about the Daylight Savings one, since that seems like it would change some important stuff in the system itself. Link to comment https://www.insanelymac.com/forum/topic/42533-security-update-2007-002-is-out/#findComment-304147 Share on other sites More sharing options...
macgirl Posted February 16, 2007 Share Posted February 16, 2007 I just tested on my AMD and it breaks, not sure about Intel. But maybe is just the Finder The other updates: Java for Mac OS X 10.4 Release 5, Daylight Saving Time Update or WebObjects 5.3.3 don't break the system. Link to comment https://www.insanelymac.com/forum/topic/42533-security-update-2007-002-is-out/#findComment-304152 Share on other sites More sharing options...
devilhood Posted February 16, 2007 Share Posted February 16, 2007 So... Intel has got the go-ahead then? Link to comment https://www.insanelymac.com/forum/topic/42533-security-update-2007-002-is-out/#findComment-304161 Share on other sites More sharing options...
chinesestunna Posted February 16, 2007 Share Posted February 16, 2007 I've just installed all updated on my laptop: Toshiba m115-s3094 Everything seems to still work Core duo 1.6 Intel 950GMA Intel 945 chipset Intel ICH7R-M southbridge Hitachi 80GB SATA HD Typing this reply in my OSX environment post update Link to comment https://www.insanelymac.com/forum/topic/42533-security-update-2007-002-is-out/#findComment-304163 Share on other sites More sharing options...
devilhood Posted February 16, 2007 Share Posted February 16, 2007 That's good enough for me *installs* *finished installing* I can also confirm that the update has not broken anything, hurrah! Link to comment https://www.insanelymac.com/forum/topic/42533-security-update-2007-002-is-out/#findComment-304167 Share on other sites More sharing options...
Urbz Posted February 16, 2007 Share Posted February 16, 2007 Yup, nothing broken on my Mac mini Core Duo or my 12" Powerbook G4. Fiewf, I was worried there! Link to comment https://www.insanelymac.com/forum/topic/42533-security-update-2007-002-is-out/#findComment-304174 Share on other sites More sharing options...
user2 Posted February 16, 2007 Share Posted February 16, 2007 (edited) All good for me Edited February 16, 2007 by user2 Link to comment https://www.insanelymac.com/forum/topic/42533-security-update-2007-002-is-out/#findComment-304177 Share on other sites More sharing options...
DiaboliK Posted February 16, 2007 Share Posted February 16, 2007 Intel Good for DL, AMD not. it messed with my windowserver.plist, but hey it was quickfix after a restart. Link to comment https://www.insanelymac.com/forum/topic/42533-security-update-2007-002-is-out/#findComment-304181 Share on other sites More sharing options...
Lostgame Posted February 16, 2007 Share Posted February 16, 2007 Yup, nothing broken on my Mac mini Core Duo or my 12" Powerbook G4.Fiewf, I was worried there! I am with you, so concerned about my MacBook, lol. Link to comment https://www.insanelymac.com/forum/topic/42533-security-update-2007-002-is-out/#findComment-304186 Share on other sites More sharing options...
i1sam Posted February 16, 2007 Share Posted February 16, 2007 I've just run a software update this am and 4 newthings comes up, to include final cut pro 5.1.3, sec updates, java etc... check it out.. just applied to my macbook cd.. my FCP still running Link to comment https://www.insanelymac.com/forum/topic/42533-security-update-2007-002-is-out/#findComment-304204 Share on other sites More sharing options...
mifki Posted February 16, 2007 Share Posted February 16, 2007 Tonight if i have some spare time, i'll patch the finder for AMD Link to comment https://www.insanelymac.com/forum/topic/42533-security-update-2007-002-is-out/#findComment-304211 Share on other sites More sharing options...
macgirl Posted February 16, 2007 Share Posted February 16, 2007 Thanks, Kiko. Link to comment https://www.insanelymac.com/forum/topic/42533-security-update-2007-002-is-out/#findComment-304219 Share on other sites More sharing options...
erbic Posted February 16, 2007 Author Share Posted February 16, 2007 (edited) Why hasn't this hit the front page yet? NEWS TEAM IS SLOW!!!!!!!!! Nothing broken on my MBP, but I expected that. I trust Apple to make fixes and such work right on their own hardware, at least. Edited February 16, 2007 by ErBiC Link to comment https://www.insanelymac.com/forum/topic/42533-security-update-2007-002-is-out/#findComment-304258 Share on other sites More sharing options...
Urbz Posted February 16, 2007 Share Posted February 16, 2007 Why hasn't this hit the front page yet? NEWS TEAM IS SLOW!!!!!!!!! I totally agree. I don't even visit the front page of this site anymore because it's so pointless. It changes once every two weeks practically! The news team seems non-existant to me... and when they take something from this board and make it "theirs" I never see blatant credit to whoever posted the original. I only check this forum for news... It's the most important! Link to comment https://www.insanelymac.com/forum/topic/42533-security-update-2007-002-is-out/#findComment-304267 Share on other sites More sharing options...
i1sam Posted February 16, 2007 Share Posted February 16, 2007 its there now... seconds ago Link to comment https://www.insanelymac.com/forum/topic/42533-security-update-2007-002-is-out/#findComment-304292 Share on other sites More sharing options...
keys88 Posted February 16, 2007 Share Posted February 16, 2007 Update is fine on my system. I also noticed that if I switch back to Windows, the system time remains accurate and is no longer 5 hours ahead. Link to comment https://www.insanelymac.com/forum/topic/42533-security-update-2007-002-is-out/#findComment-304318 Share on other sites More sharing options...
my1stmacisaHACK Posted February 16, 2007 Share Posted February 16, 2007 no amd path yet? im itching my hands on it!! Link to comment https://www.insanelymac.com/forum/topic/42533-security-update-2007-002-is-out/#findComment-304412 Share on other sites More sharing options...
CoolBits Posted February 16, 2007 Share Posted February 16, 2007 no amd path yet? im itching my hands on it!! Check here http://forum.insanelymac.com/index.php?sho...c=42521&hl= Link to comment https://www.insanelymac.com/forum/topic/42533-security-update-2007-002-is-out/#findComment-304417 Share on other sites More sharing options...
mifki Posted February 16, 2007 Share Posted February 16, 2007 there is a patch, check in the other thread about this, coolbits made it LOL: Beat me again Link to comment https://www.insanelymac.com/forum/topic/42533-security-update-2007-002-is-out/#findComment-304419 Share on other sites More sharing options...
CoolBits Posted February 16, 2007 Share Posted February 16, 2007 interesting Link to comment https://www.insanelymac.com/forum/topic/42533-security-update-2007-002-is-out/#findComment-304422 Share on other sites More sharing options...
quixos Posted February 16, 2007 Share Posted February 16, 2007 you know, i don't feel like updating. perhaps i have a fever or something. Link to comment https://www.insanelymac.com/forum/topic/42533-security-update-2007-002-is-out/#findComment-304445 Share on other sites More sharing options...
my1stmacisaHACK Posted February 16, 2007 Share Posted February 16, 2007 (edited) hey the first sec update.. is it okay to update w/ AMDs? Edited February 16, 2007 by my1stmacisaHACK Link to comment https://www.insanelymac.com/forum/topic/42533-security-update-2007-002-is-out/#findComment-304457 Share on other sites More sharing options...
Recommended Posts