🦞🌯 Lobster Roll

Thread

About the security content of Security Update 2017-001 (fixes local root auth bypass) (support.apple.com)
This update fixes the `root`/no password auth bypass issue. I guess if you read this and you're running High Sierra, you should check your OS release (it should be `17B1002`), and if it's vulnerable, check for updates immediately.

Stories related to "About the security content of Security Update 2017-001 (fixes local root auth bypass)" across the full archive.

About the security content of Security Update 2017-001 (fixes local root auth bypass) (support.apple.com)
This update fixes the `root`/no password auth bypass issue. I guess if you read this and you're running High Sierra, you should check your OS release (it should be `17B1002`), and if it's vulnerable, check for updates immediately.
PostgreSQL: 2017-05-11 Security Update Release (postgresql.org)
Updated NIST Guidance For Bluetooth Security, July 2017 (csrc.nist.gov)
Dropbox security update & new features (blog.dropbox.com)
New security issue affecting Java SE 7 Update 7 (full JVM sandbox bypass) (seclists.org)
Rails 3.0.20, and 2.3.16 have been released - critical security updates (weblog.rubyonrails.org)
About the security content of OS X Mavericks v10.9 (support.apple.com)
Conceptual Security Flaw in googles e2e: incompatible with Chrome Update functionality (code.google.com)
On WebKit Security Updates (blogs.gnome.org)
Reflecting on Recent iOS and Android Security Updates (blog.zimperium.com)
Security update for IntelliJ-based IDEs v2016.1 and older versions (blog.jetbrains.com)
Out-of-Box Exploitation: A Security Analysis of OEM Updaters (wired.com)
Out-of-Box Exploitation: A Security Analysis of OEM Updaters (duo.com)
Update your Apple devices now to fix a terrifying security bug (qz.com)
RWC 2017 - Is Password Insecurity Inevitable? (bristolcrypto.blogspot.com)
Security Update for the LastPass Extension (blog.lastpass.com)
Zcash - Security Announcement 2017-04-12 (z.cash)
Study on Mobile Device Security, April 2017 (dhs.gov)
Verification of a practical, hardware, security architecture through static, info-flow analysis 2017 (cs.cornell.edu)
Guide to Automatic Security Updates For PHP Developers (paragonie.com)
nginx 1.13.3 & 1.12.1 released - security advisory (CVE-2017-7529) (mailman.nginx.org)
Security advisory for crates.io, 2017-09-19 (users.rust-lang.org)
Qualys Security Advisory - Linux PIE/stack corruption (CVE-2017-1000253) (openwall.com)
Sancus: A Low-Cost, Security Architecture for IoT Devices (2017) (esat.kuleuven.be)
Security Education in Uncertain Times: 2017 in Review (eff.org)
Important: Windows security updates released January 3, 2018, and antivirus software (support.microsoft.com)
Microsoft is only offering the Windows security updates that were released on January 3, 2018, to devices that are running antivirus software that is from partners who have confirmed that their software is compatible with the January 2018 Windows operating system security update.
CVE-2017-17482: OpenVMS Security Notice for local privilege escalation (groups.google.com)
Title edited since the original posting wasn't entirely detailed. There is also an article on the register: https://www.theregister.co.uk/2018/02/06/openvms_vulnerability/
Identifying Security Critical Properties for the Dynamic Verification of a Processor (2017) (cs.unc.edu)
Android Security: 2017 Year in Review (source.android.com)
Beep Security Update for Debian 7 LTS (linuxcompatible.org)
Today's Unix enormity.