An open community 
of Macintosh users,
for Macintosh users.

FineTunedMac Dashboard widget now available! Download Here

Previous Thread
Next Thread
Print Thread
Bad News for Older Versions of OS X
#33776 04/10/15 05:18 PM
Joined: Aug 2009
Likes: 16
Moderator
OP Online
Moderator

Joined: Aug 2009
Likes: 16
Are you still going to hang on to your old version of OS X if this Engadget article is true?


If we knew what it was we were doing, it wouldn't be called research, would it?

— Albert Einstein
Re: Bad News for Older Versions of OS X
joemikeb #33778 04/10/15 05:41 PM
Joined: Aug 2009
Offline

Joined: Aug 2009
companies not fixing security holes in non-current software really isn't anything new. If you gave me some time I could probably come up with a fairly long list of bugs not fixed in prior Mac OS X's. I can really only think of a single example of Apple releasing a security update for an X that was more than one version back.


I work for the Department of Redundancy Department
Re: Bad News for Older Versions of OS X
joemikeb #33780 04/10/15 06:48 PM
Joined: Aug 2009
Likes: 4
Offline

Joined: Aug 2009
Likes: 4
Originally Posted By: joemikeb
Are you still going to hang on to your old version of OS X if this Engadget article is true?

Just how serious is it if the flaw "was discovered ... back in October, but has actually existed since at least 2011"?

And if the flaw involves System Preferences internal to OS X, how might some nefarious sort gain access to it if one locks out unauthorized access (via OS X's firewall and sharing nothing with the outside world)?

Re: Bad News for Older Versions of OS X
Virtual1 #33781 04/10/15 09:48 PM
Joined: Aug 2009
Likes: 15
Online

Joined: Aug 2009
Likes: 15
Originally Posted By: Virtual1
companies not fixing security holes in non-current software really isn't anything new.

Security Update 2015-002 was issued for Mounty, Mavericks & Yosemite, and 2015-004 was issued for Mounty, Mavericks & (I assume) Yosemite (via the 10.10.3 Update issued on the same day), so issuing 2015-005 for Yosemite only would be pretty shabby of Apple...but not atypical.

Last edited by artie505; 04/11/15 12:38 AM. Reason: Clarity

The new Great Equalizer is the SEND button.

In Memory of Harv: Those who can make you believe absurdities can make you commit atrocities. ~Voltaire
Re: Bad News for Older Versions of OS X
artie505 #33785 04/11/15 12:22 AM
Joined: Aug 2009
Likes: 3
Moderator
Offline
Moderator

Joined: Aug 2009
Likes: 3

There is no Security Update 2015-005. The patch under discussion is the first item listed in the OS X Yosemite v10.10.3 and Security Update 2015-004.



dkmarsh—member, FineTunedMac Co-op Board of Directors
Re: Bad News for Older Versions of OS X
dkmarsh #33787 04/11/15 12:36 AM
Joined: Aug 2009
Likes: 15
Online

Joined: Aug 2009
Likes: 15
I was anticipating a 2015-005 update (...should have put it in quotes) because I did a typically lousy job digesting joemike's linked article and it didn't register that a fix was already in place. crazy

Last edited by artie505; 04/11/15 07:23 AM. Reason: Corrections

The new Great Equalizer is the SEND button.

In Memory of Harv: Those who can make you believe absurdities can make you commit atrocities. ~Voltaire
Re: Bad News for Older Versions of OS X
dkmarsh #33789 04/11/15 07:18 AM
Joined: Aug 2009
Likes: 15
Online

Joined: Aug 2009
Likes: 15
Originally Posted By: dkmarsh
The patch under discussion is the first item listed in the OS X Yosemite v10.10.3 and Security Update 2015-004.

That patch

Originally Posted By: Apple
Admin Framework
Available for: OS X Yosemite v10.10 to v10.10.2
Impact: A process may gain admin privileges without properly authenticating
Description: An issue existed when checking XPC entitlements. This issue was addressed with improved entitlement checking.
CVE-ID
CVE-2015-1130 : Emil Kvarnhammar at TrueSec
(Emphasis added)

applies exclusively to Yosemite.

Doesn't that mean that Apple has effectively dropped support for Mavericks and Mounty (Security Update 2015-004 notwithstanding), despite the fact that OS X 10.11 hasn't even been announced, let alone released, or are they still "supporting" those versions of OS X but only in part? shocked


The new Great Equalizer is the SEND button.

In Memory of Harv: Those who can make you believe absurdities can make you commit atrocities. ~Voltaire

Moderated by  alternaut, cyn 

Link Copied to Clipboard
Powered by UBB.threads™ PHP Forum Software 7.7.4
(Release build 20200307)
Responsive Width:

PHP: 7.4.33 Page Time: 0.021s Queries: 28 (0.014s) Memory: 0.6019 MB (Peak: 0.6734 MB) Data Comp: Zlib Server Time: 2024-04-27 00:38:29 UTC
Valid HTML 5 and Valid CSS