Adsense

Showing posts with label 2014 at 09:46PM. Show all posts
Showing posts with label 2014 at 09:46PM. Show all posts
Apple today released OS X bash update 1.0 for OS X Mavericks to fix a vulnerability in the bash UNIX shell.



The security flaw, known in the media as "Shellshock," was discovered last week. Uncovered by security researchers, the exploit in the bash command shell in OS X and Linux could be used to deploy malicious code.



bashupdate

According to an Apple spokesperson, most OS X users were not at risk form the bash vulnerabilities, but the company promised to work quickly to provide an update.
Bash, a UNIX command shell and language included in OS X, has a weakness that could allow unauthorized users to remotely gain control of vulnerable systems. With OS X, systems are safe by default and not exposed to remote exploits of bash unless users configure advanced UNIX services. We are working to quickly provide a software update for our advanced UNIX users.

Along with the fix for OS X Mavericks, Apple has released updates for both OS X Lion and OS X Mountain Lion. There is no Yosemite download available as of yet, but Apple may be planning to issue a fix in the near future. The three updates are available via Apple's support pages and should be available via the Software Update tool soon.


















Mentions of new iMac models are buried inside the OS X Mavericks 10.9.4 beta that was seeded earlier today.



There are three new resource files for power management that mention three new iMacs with model numbers beginning with 15, according to some digging done by Pike's Universum. The current iMac line is made up of models 14,1 and 14,2.



Imacs
The most interesting part is the addition of three new resources (plist) files for power management:



Mac-81E3E92DD6088272.plist / iMac15,1 (IGPU only)

Mac-42FD25EABCABB274.plist / iMac15,n (IGPU/GFX0/Apple display with id 0xAE03)

Mac-FA842E06C61E91C5.plist / iMac15,n (IGPU/GFX0/Apple display with id 0xAE03)

Rumors have suggested that new iMac models could make an appearance at WWDC next week after shipping estimates for the machine began to slip on the Apple Online Store.


















airport_utility_iconApple today released AirPort Extreme and AirPort Time Capsule Firmware Update 7.7.3 for AirPorts with 802.11ac. The update includes security improvements related to SSL/TLS.

AirPort Base Station Firmware Update 7.7.3

Available for: AirPort Extreme and AirPort Time Capsule base stations with 802.11ac



Impact: An attacker in a privileged network position may obtain memory contents



Description: An out-of-bounds read issue existed in the OpenSSL library when handling TLS heartbeat extension packets. An attacker in a privileged network position could obtain information from process memory. This issue was addressed through additional bounds checking. Only AirPort Extreme and AirPort Time Capsule base stations with 802.11ac are affected, and only if they have Back to My Mac or Send Diagnostics enabled. Other AirPort base stations are not impacted by this issue.

Earlier this month, an OpenSSL bug known as Heartbleed made headlines, with Apple releasing a statement noting that iOS, OS X, and its "key web services" were unaffected by the security flaw, but it appears that the company's AirPort Extreme and AirPort Time Capsule were vulnerable.



The 7.7.3 update is recommended for all models of the AirPort Extreme and Time Capsule that support 802.11ac Wi-Fi, other AirPort base stations do not need to be updated.


















Adsense