Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: Swordmaker

Right, well, the author of this article seemed to think it newsworthy because of the severity of the security patches provided on this one this time about, so it seemed worthy of noting at least. Thanks for the feedback.

Cheers.


10 posted on 07/01/2015 7:41:34 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them)
[ Post Reply | Private Reply | To 9 | View Replies ]


To: Utilizer
Right, well, the author of this article seemed to think it newsworthy because of the severity of the security patches provided on this one this time about, so it seemed worthy of noting at least. Thanks for the feedback.

They are no more severe than other vulnerabilities that were fixed in the past. None of these rose to the level of being actually exploited in the wild. . . and most required physical possession of the machine to exploit. The vast majority of the fixes are minor. Some of them, such as the RowHammer vulnerability affected Linux, Windows, and OS X. . . but it was an extremely hard vulnerability to exploit. It just needed to be fixed. The article postulated that someone "could use" Rowhammer to escalate privileges. No, it could not, because it takes a lot more than just flipping a few memory locations to do that. Just disrupting some RAM will not accomplish that. Still, as i said, it needed to be fixed. Apple found a way to avoid even the possibility of attack.

Logjam is a problem with SSL layers at all levels of the Internet. . . and essentially this is a systemic problem that requires more than just a solution at the OS level. Apple has done what it can. Now servers and IPS operators have to do theirs.

These are all in the sense of closing the vulnerabilities before the exploits exist. This is a proactive approach to security.

12 posted on 07/01/2015 8:45:51 PM PDT by Swordmaker ( This tag line is a Microsoft insult free zone... but if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 10 | View Replies ]

To: Utilizer
Right, well, the author of this article seemed to think it newsworthy because of the severity of the security patches provided on this one this time about, so it seemed worthy of noting at least. Thanks for the feedback.

Incidentally, Apple includes in their updates to OS X and iOS security update fixes for all the components of UNIX™ that are shipped with OS X, plus fixes for additional software that ships with Apple software. That tends to inflate the number of CVEs that are reported in the updates.

Cheers, right back to you, too. Enjoy the holiday week. . .

13 posted on 07/01/2015 8:49:51 PM PDT by Swordmaker ( This tag line is a Microsoft insult free zone... but if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 10 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson