Posted on 02/15/2007 4:42:57 PM PST by JohnSheppard
Apple today released Security Update 2007-002 to fix several vulnerabilities affecting the Mac OS X Finder, iChat, and the UserNotificationCenter process. One vulnerability could cause an application to crash or result in arbitrary code execution, resuming the user is enticed into opening a specially-crafted disk image resulting in a buffer overflow in Finder's handling of volume names. Two iChat-related security concerns are fixed in the update, preventing attackers on the local network from causing iChat to crash and foiling potential attempts by malicious websites to cause applications to crash or execute arbitrary code. The UserNotificationCenter process runs with elevated privileges in the context of local users, potentially allowing a malicious local user to overwrite or modify system files prior to the update. The update is available for download from Apple's website, as well as via the "Software Update" feature in Mac OS X located under the Apple menu.
(Excerpt) Read more at macnn.com ...
Apple offers Java, daylight savings updates
Apple today updated the way Mac OS X handles Daylight Saving Time for Tiger (and DST for Mac OS X 10.3 Panther) and updated Java for Mac OS X 10.4 (and Java for Mac OS X 10.3 Panther) to add support for those same changes. The Daylight Saving Time update reflects changes in several countries and regions that will alter the dates on which they observe Daylight Saving Time, while the Java for Mac OS X 10.4 Release 5 adds support for the latest Daylight Saving Time changes and time zone information. The Java update also provides improved reliability and compatibility for Java 2 Platform Standard Edition 5.0 and Java 1.4 on Mac OS X 10.4.8 and later. The release updates J2SE 5.0 to version 1.5.0_07 and Java 1.4 to version 1.4.2_12, improving reliability of the SWT_AWT bridge implementation first released in the SWT Compatibility Libraries for Release 4. The improvement is installed as a standard part of J2SE 5.0, according to Apple.
Apple ping
so many bugz, so little fixes...
But we've all been told that Apple has no need for fixes.
Even Moses used "Wite-Out" ;) LOL
Security
Java
Daylight Savings Time change
If you want on or off the Mac Ping List, Freepmail me.
No one has ever said that on FreeRepublic... or on any of the Apple forums that I have read (lots). It is a strawman usually stated by Windows fans.
Thanks for the ping!
and...it is FREE!!
I just love the friendly banter amongst the various factions!
What are we supposed to do when we're running BOTH XP and Mac?
Just make sure PC Guy plays nice with Mac Guy!
For all you Mac users out there... don't worry about this. Security vulnerabilities only happen on PC's. No need to update.
If they are both on a Mac, I understand there might be a problem with the clocks. Because of the ways each system handles the system clock, I believe you have to wait for the PC to reset the clock after rebooting with Boot Camp... and vice-verse into the Mac. The Mac checks the clock on boot up. The PC apparently doesn't but instead does it on a schedule something like every half hour. Parallels will use the Mac clock.
Microsoft will have an update for handling the political driven change in daylight savings time. I wonder if MS will update W98, W2000, WME, etc.
Vulnerabilities occur on both systems... but so far only PCs have in-the-wild exploits of those vulnerabilities.
Yah. Ok.
I actually don't have a dog in this fight. I'm a big fan and user of Windows, Mac, Linux, Unix and a little VMS. They've all got their good and bad points and they've each got their place in the enterprise.
But what cracks me up are the mac users that continue to live in a totally pants-down dreamland of invulnerability. The inevitability of the eventual reality check will be difficult not to pounce on with much mirth and celebration.
But I was a machead first. So it is with sadness, too.
:-)
There's been patches out for the DST clock thing for months for at least Windows 2000 and up. I haven't checked about W98 or prior since I don't have any users on those antiques.
But then again, Apple doesn't have a DST patch for System 6 or 7, either.
Please do us all a favor and find that post.
We'll wait.
I'm sure we'd all like to see that post as well.
Don't worry, we'll wait.
It's on all the commercials, dude...
Most Unix systems actually run the system clock as GMT, with the time you are displayed being an offset from GMT based on an environment variable or a localization configuration file. This is why you can have Alice in San Diego and Bob in Dallas, and Charlie in Orlando login to the same system, and each have their local time displayed to them (providing, of course they have their TZ environment variable set, as should be the case if you have folks from across the country, or world logging into one system.
Why not just have the start/stop date and offset in a file so folks wouln't have to worry as much the next time the idiots in Washington decide they know better than God does about what time the sun should rise and set. Sometimes the arrogance of the criminals that populate that city astounds me. To protect ourselves from future declarations against nature, we should make it as easy as possible to deal with their lunacy.
Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.