Security Update Fixes the Screen Effects Hole 94
jellomizer writes "Here is is. Available from Software Update. 'Security Update 2003-07-14 addresses a potential vulnerability when a password is required upon waking from the Screen Effects feature, which could allow an unauthorized user access to the desktop of the logged in user.'
Now we can use our screen savers with the warm and fuzzy secure feeling."
went witout a hitch (Score:4, Interesting)
Re:went witout a hitch (Score:5, Funny)
i just hope that one day updates won't require a restart.
Ain't it annoying? How the hell am I going to get my uptime past 30 days or so if I keep having to restart because of patches? Curse you, Apple, for fixing things on a regular basis!!
Re:went witout a hitch (Score:5, Informative)
1. download and install the patch. 2. log out, if you can. 3. type ">console" or maybe even ">exit" in the user name field of the login window. 4. once in the console, I believe a ctl-D will restart the login window.
Re:went witout a hitch (Score:5, Insightful)
Re:went witout a hitch (Score:2, Interesting)
So... some folks do have a lot more to worry about than the GUI. Sure, I could just run Darwin, but I do a small amount of stuff that requires a GUI too.
Re:went witout a hitch (Score:1, Insightful)
Re:went witout a hitch (Score:4, Funny)
Re:went witout a hitch (Score:1)
Re:went witout a hitch (Score:1)
Re:went witout a hitch (Score:1)
Re:went witout a hitch (Score:5, Informative)
You have to remember that this is an operating system for the masses and their desktops. I'm sure this update could've not required a restart, but what if something went wrong? Would your grandmother know how to make sure the current version of a shared library is loaded for her applications?
Re:went witout a hitch (Score:1, Insightful)
When installing a new daemon it may run quite well initially, but until it's started up through the normal boot
Re:went witout a hitch (Score:5, Informative)
% sudo softwareupdate SecurityUpd2003-07-14-1.0
[wait for install to finish]
Installing "Security Update 2003-07-14"... 98% 98% 99% 99% 99% 99% done.
You have installed one or more updates that requires that you restart your
computer. Please restart immediately.
Re:went witout a hitch (Score:5, Insightful)
That is not true. No reboot is required. (Score:2, Informative)
Have you tried it? I have. No reboot, and no more crashing screen saver.
Anything that is already running retains the old version of Security.framework until it's started again, but ScreenSaverEngine.app and loginwindow are both immune. There may be other (unrealized? unreported?) exploits that the update fixes that require a logout or reboot, but to fix
Re:That is not true. No reboot is required. (Score:2)
Re:went witout a hitch (Score:1)
Re:went witout a hitch (Score:2)
But if you feel as I do that the bug this update addresses is trivial, skipping the eboot makes sense. Install it and forget it, then simply let it take effect when you next need to reboot. Or wait; it's up to you.
Maybe better to wait; sometimes the damndest things... happen.
Re:went witout a hitch (Score:1)
Re:went witout a hitch (Score:1)
I'm not being sarcastic here... but have you complained yet to Apple? I know that the person who disclosed the original problem (the buffer overflow in the password feild, was it?) expresssed dismay that Apple hadn't responded to him. But here we are two weeks after the public disclosure and there's at least a partial fix for what (forgive me) is a slight problem that requir
Re:went witout a hitch (Score:3, Interesting)
Re:went witout a hitch (Score:1)
Re:went witout a hitch (Score:1)
Re:went witout a hitch (Score:1)
Them Apple Switchers (Score:3, Funny)
ain't they well informed
goin' to and frow,
switchn' they platform.
Them banjo pickin' Apple Switchers,
see how much they spent?
They switch to stop blue screens of death
or just to Think Different.
Look at all those Apple Switchers,
hey they even chicks!
Some just switch to make a point,
some just for the kicks.
How to be an Apple Switcher,
if you want to know?
Take a trip to Apple's store
and pony up the dough.
Yee and/or Haw as needed (Score:1)
W h e r e . . . (Score:5, Funny)
Sure can tell its Monday afternoon - editors are still recovering from the weekend
Could pudge or jellomizer please post a hyperlink? Thanks!
Re:W h e r e . . . (Score:5, Funny)
Does this fix the problem globally? (Score:5, Interesting)
It appears to (Score:3, Informative)
Re:It appears to (Score:5, Informative)
Trying to reduce the public's perception of the problem are we Apple?
Just think, a Cocoa buffer overflow still isn't as bad as Windows' shatter attacks.
Re:It appears to (Score:5, Informative)
I'm not convinced there was ever a general cocoa problem.
Obviously, there was the screensaver bug, and I reproduced that myself.
Other people mentioned a problem with the login window. I've noticed before if I type an incorrect password it drops to a text-console. This is what people observed when trying to overflow the login window. It's certainly not an exploit.
I tried overflowing text fields in safari and mail, without incident.
If someone really found another app that was affected as the screensaver was, I'd really like to hear about it.
Unless someone does, I'll give apple the benefit of the doubt. They fixed the problem, no harm no foul.
Re:It appears to (Score:3, Informative)
The bug seemed to be only on specific versions of Darwin/OS X and was a bit strange even then.
Either way, at least one potential bug is crushed.
Re:It appears to (Score:2)
I agree that a buffer overflow in the login window would be bad. I've just seen no evidence that the login crashes are linked to a buffer overflow or are the same as the screensaver problem.
I've "crashed" the login screen by just entering the wrong password - not a buffer overflow, I'd not suspect.
The people who reported crashing the login window did the same thing...they entered an incorrect password. I don't think it's length had anything to do with the reported behavior. That's my only point.
You could crash Mail (Score:1)
It's fixed now.
Re:Broke My iChat (Score:1)
Since I don't use iChat often, I guess it really doesn't matter to me. Just hope no other apps have weird reactions, though.
Versions (Score:5, Interesting)
Re:Versions (Score:5, Informative)
Anybody have any idea what files this updates and what version it updates those files to?
This is what the package contains. I haven't installed it, so I don't know what the new versions are.
Listing files for Security Update 2003-07-14Re:Versions (Score:4, Informative)
Re:Quick question here (Score:2, Insightful)
Didn't think so, asshole. Try again.
The task that hdparm performs can be performed and still have an interface that isn't nearly that cryptic. The interface can be optional, for those users who would prefer to impress their fellow virgins at their mastery of arcane commands.
The concept that the Linux crowd seems to have missed (but that Apple has embraced) is that you can have two ways of doing things:
1) The Easy Way.
2) The Hard Way.
The two need no
Re:Quick question here (Score:1)
Meanwhile, he seems to be from the future, with an Opteron which isn't availible yet, along with MacOS X 10.3 (Panther)
Athlon64 XP -3000+, wha?
Here's a reason this IS important (Score:5, Interesting)
Re:Here's a reason this IS important (Score:3, Interesting)
I don't notice a performance hit (Score:4, Informative)
Re:I don't notice a performance hit (Score:2)
FileVault? (Score:3, Interesting)
I should get credit! (Score:1)
As for whether or not I'll use FileVault, that remains to be seen... I have yet to get ahold of panther (since it's not been released yet) so I don't know if FileVault will suit my needs.
Re:I should get credit! (Score:2)
That was a feature I thought was really an innovative in Panther, one of those, "Why didn't I
Sounds almost like what I need... (Score:1)
As for my thinking of
For those preferring to not use SU (Score:5, Informative)
Re:For those preferring to not use SU (Score:2)
I prefer to use Software Update...
HTTP download it is.
Re:Please, why choose Mac? (Score:3, Funny)
In addition, during reading the parent troll, I will not work. And everything else has groun
Problem? (Score:5, Informative)
So instead you power cycle the laptop, hold down S durring boot to enter single user mode.
At this point you do technically have root, although without a GUI.
Change target accounts password, reboot, login.
If you have a password set in openfirmware to prevent single user mode boots, I have to zap the pram 3 times and the password is gone.
Granted this is a whole lot harder than breaking the screen saver, but still, any computer someone can get physical access to is not secure under any conditions.
Re:Problem? (Score:2, Informative)
Yeah, but you can't do that via cmd-opt-P-R (or the OF command line) if there's an OF password set. You have to crack the case.
WM
Re:Problem? (Score:5, Insightful)
a) The possibility of this being used maliciously required physical access, and other physical methods rendered it near moot.
b) This point is hard to get across when the news report reads "Apple has security failure from locked screen savers", and therefore may as well be fixed.
c) Being a buffer problem in a shared library, it is possible that something else, either presently or in the future, would also become vulnerable. This is probably the best reason to fix it while the risk is still light.
It is a problem (Score:2, Interesting)
...and... (Score:5, Informative)
No restart needed!!
Re:...and... (Score:3, Informative)
*yawn* gory details... (Score:4, Informative)
The download file is named: "SecurityUpd2003-07-14.dmg
Its SHA-1 digest is: 210f4819b8559b590632cd62b4055a437b9a0267
restart (Score:3, Interesting)
Re:restart (Score:5, Informative)
Re:restart (Score:2, Informative)
As mentioned before, there's not much reason to run the updater if you're not going to reboot right away. Yeah, yeah, maybe sometimes there's some reason, but generally not.
Re:restart (Score:1, Informative)
Just like any other application, Software Update can be forced to quit. When it finishes writing out the update to disc and asks you to restart, just force quit Software Update and restart your computer when you're done with whatever you're busy with.
WAIT A MINUTE HERE (!) (Score:5, Funny)
Oh, wait, I stopped using Microsoft products. Sorry.
Print center now broken (Score:2, Interesting)
WARNING : FLAME IN PROGRESS (Score:1)
With that spelling you could write for the NY Times
.
Security Vulnerabilities? (Score:1)
nobody seems to be screaming that Apple is stupid and lazy. In fact, I see more Microsoft security bashing here that Apple security bashing.
But... isn't the error with Apple software?
So... why aren't you all screaming at the horrible evil that is Apple?
Not that I think Apple is either of those things, mind you. Or at least not in relation to this issue. I just think that the obscene amount of Microsoft bashing is 20% based on their problems and business practices, and 80% because of jealousy th
simple (Score:1)
Re:Security Vulnerabilities? (Score:1)
Re:Security Vulnerabilities? (Score:2)
... and then this one time, at band camp...