Looks like that Apple TV update from this morning, which bestowed/cursed the device with the glory/damnation that is YouTube also had another little payload on it in the form of the Apple TV’s first security update.
According to Apple, the download (dubbed Apple TV 1.1) contains a patch for a buffer overflow vulnerability in the UPnP (Universal Plug and Play) system that could let a remote attacker cause a denial of service or possibly execute random arbitrary code. The Register notes that the same vulnerability was patched last month in OS X by Security Update 2007-005. The download is only available via the Apple TV’s built-in software update; you can wait for it to run automatically, or you can tell it to update manually.
We’d also like to note that Apple’s site credits Michael Lynn of Juniper Networks for reporting the flaw, despite the accusation by some that Apple has inveterately threatened security researchers into silence. Ahem.
[via Mac Surfer]
MacUser is your source for news, info, and opinion about Apple, the Mac, and the iPod. Our dedicated team of bloggers covers everything that is relevant to Mac users — and, okay, some stuff that’s not quite relevant, but is still a lot of fun.
Leave a comment