Sponsored in part by... Readers Like You! READERS LIKE YOU! Support TidBITS with a contribution today!
<http://www.tidbits.com/about/support/contributors.html>
Special thanks this week to John O'Shaughnessy, Bob Dolan,
Robin S. Armstrong, and David M. Douds for their generous support!

 [F] TidBITS  / TidBITS  / TidBITS Talk  /

Problems with Security Update 2004-06-07

[Engst, Adam]Adam Engst - 04:14pm Jun 10, 2004 PST

The first problem I've heard of. This security patch does low-level
stuff, so I won't be at all surprised to see more such reports.

<http://db.tidbits.com/getbits.acgi?tbart=07693>

cheers... -Adam

--- begin forwarded text

From: "Bill Gerber"
Date: Wed, 9 Jun 2004 12:17:43 -0700

I read your June 8th issue and your commentary about the latest security
patch.

I installed this patch yesterday on my Pismo running OS-X 10.3.4. Now,
each time that I try to launch my ancient "BulkRate v2.6b6" I get a notice
that it will be opened for the first time, and giving me the opportunity
to cancel if I wish.

This is all well and good, but alerting me once was enough. It would be
much appreciated if the OS would remember that I said "yes" to this before
and bypass the notice thereafter; or at least give me the opportunity to
"check" a box allowing it to bypass the notice for this specific
application "from this day forward".

My $0.02, FWIW.

Bill Gerber

--- end forwarded text


Mark as Read
  OutlineAll MessagesOlder MessagesOldest MessagesNewest MessagesNewer Messages

bitreader - Jun 10, 2004 4:15 pm (#1 Total: 7)  

Reply to this message
 

Photo of Author
Posts: 120
Re: Launch Services Holes

The TidBITS article describing Security Update 2004-06-07 says:

It also removes the registration of the disk URL scheme so disk images accessed via disk URLs no longer mount automatically.

Which matches the information found at <http://docs.info.apple.com/article.html?artnum=61798>

which states:

Discussion: The registration of the disk:// URI type is removed from the system as a preventative measure against attempts to automatically mount remote disk image file systems.

But these statements do not match my experience.

After installing Security Update 2004-06-07 I did the following:

Opened RCDefaultApp (version 1.1.1) Clicked the URL Button Scrolled throught the list of protocols checking the status of each Reset the afp protocol to Finder Reset the disk protocol to Disk Copy went to <http://test.doit.wisc.edu/> to test the afp and disk exploits

When I click the disk link just below the automated example heading

I see a DiskCopy start up and mount a disk image. DiskCopy responds with a dialog telling me "test.dmb" was successfully mounted. This is almost immediatedly followed by an alert with boldface type that reads

The Internet location you are openning will open the application "test" for the first time. Are you sure you want to open this application?

From this I conclude the disk:// URI has not been removed. It is still possible for disk images to mount automatically. But the vulnerability no longer exists.

I do note the disks:// URI that was present when I first installed RCDefaultApp no longer seems to exist.

John C. Welch (apparently) - Jun 12, 2004 4:33 am (#2 Total: 7)  

Reply to this message
via email  

Photo of Author
Posts: 858
Re: Problems with Security Update 2004-06-07

On 6/10/04 6:15 PM, "bitreader" <bitreaderearthlink.net> wrote:

> From this I conclude the disk:// URI has not been removed. It is still
> possible for disk images to mount automatically. But the vulnerability no
> longer exists.
>
> I do note the disks:// URI that was present when I first installed
> RCDefaultApp no longer seems to exist.

If you have Disk Copy installed, that messes things up, since that is not a
part of Panther, but part of jaguar.

john

--
John C. Welch Writer/Analyst
Bynkii.com Mac and other opinions
jwelchbynkii.com


Nigel Stanger (apparently) - Jun 12, 2004 4:33 am (#3 Total: 7)  

Reply to this message
via email - Dunedin, New Zealand  

Photo of Author
Posts: 446
Re: Problems with Security Update 2004-06-07

On 11/6/2004 11:15 AM, "bitreader" <bitreaderearthlink.net> spake thus:

> From this I conclude the disk:// URI has not been removed. It is still
> possible for disk images to mount automatically. But the vulnerability no
> longer exists.
>
> I do note the disks:// URI that was present when I first installed
> RCDefaultApp no longer seems to exist.

I can confirm (using RCDefaultApp) that on my system, both the disks:// or
disk:// URI schemes have vanished. Obviously something unusual has happened
in your case.

--
=Nigel Stanger, Dunedin, NEW ZEALAND.
mailto:nstangerinfoscience.otago.ac.nz

albo (apparently) - Jun 12, 2004 4:33 am (#4 Total: 7)  

Reply to this message
via email  

Photo of Author
Posts: 6
Re: Problems with Security Update 2004-06-07

Hi,
I'm having the same problems that Bill is: on my G4/400 OS10.2.8, when
I double-click a file to open an app I get the "this is the first
time..." message. It looks like this is happening with non-Apple apps.
Also the icons for files created in these apps have reverted to
low-quality images of previous versions of the app... until I go through
process of opening the app for the first time at which point they revert
to the higher-quality icon for the current version of the app. The apps
will open from the Dock the first time without going through the "first
time.." song and dance, and it seems to solve the problem for that app.
Weird, but I'm glad to know why this is happening!
Albo

>

baltwo - Jun 12, 2004 4:33 am (#5 Total: 7)  

Reply to this message
 

Photo of Author
Posts: 33
Re: Launch Services Holes

On 06/10/04, bitreader wrote:

The TidBITS article describing Security Update 2004-06-07 says... But these statements do not match my experience.


Then you need to update the LaunchServices database. See the article at <http://www.theregister.com/2004/06/09/apple_security/> and the update procedure at <http://www.macosxhints.com/article.php?story=20031215144430486>.

bitreader (apparently) - Jun 14, 2004 9:43 am (#6 Total: 7)  

Reply to this message
via email  

Photo of Author
Posts: 120
Re: Problems with Security Update 2004-06-07

On 6/12/04 at 4:33 AM, albocritpath.org (albo) wrote:

>Hi, I'm having the same problems that Bill is: on my G4/400
>OS10.2.8, when I double-click a file to open an app I get the
>"this is the first time..." message.

Although this isn't the issue I was describing, I do see this occurring. But if I understand the patch correctly this is to be expected.

My understanding is the "this is the first time ... " message appears whenever an application is launched via Launch Services rather than directly by double clicking on it. When you launch an application by double clicking on a file, you are using Launch Services to launch the application.

But this should only happen if the first time you use an application after installing the security update it is launched via Launch Services. Once you allow the application to open, you should no longer get the message and the application should launch as it did before installing the security update.

bitreader (apparently) - Jun 14, 2004 9:43 am (#7 Total: 7)  

Reply to this message
via email  

Photo of Author
Posts: 120
Re: Problems with Security Update 2004-06-07

On 6/12/04 at 4:33 AM, jwelchbynkii.com (John C. Welch) wrote:

>If you have Disk Copy installed, that messes things up, since that
>is not a part of Panther, but part of jaguar.

I do have Disk Copy installed and I am running Panther. So, this may well be the reason I did not see the disk:// URL removed. But this makes me wonder what those running Jaguar would see. The description of the security update doesn't indicate the disk:// URL would be removed for Panther and not Jaguar which is what should be expected if you are correct.



  OutlineAll MessagesOlder MessagesOldest MessagesNewest MessagesNewer Messages


 [F] TidBITS  / TidBITS  / TidBITS Talk  / Problems with Security Update 2004-06-07




Add a message

To add a message to this discussion, you must be a registered user. Enter your email address below. If you have an account associated with the email address you enter, you will be prompted for your password. If not, you'll be able to create a new account with no fuss.

Enter your email address:

Submit