Apple Issues Patch for Critical NTP Vulnerability

Apple NTP Security Update 20141222

Apple issues OS X NTP Security Update for Mountain LionMavericks and Yosemite.

OS X NTP Security Update
ntpd

Available for: OS X Mountain Lion v10.8.5, OS X Mavericks v10.9.5, OS X Yosemite v10.10.1

Impact: A remote attacker may be able to execute arbitrary code

Description: Several issues existed in ntpd that would have allowed an attacker to trigger buffer overflows. These issues were addressed through improved error checking.

To verify the ntpd version, type the following command in Terminal: what /usr/sbin/ntpd. This update includes the following versions:

Mountain Lion: ntp-77.1.1
Mavericks: ntp-88.1.1
Yosemite: ntp-92.5.1

CVE-ID

CVE-2014-9295 : Stephen Roettger of the Google Security Team

From ICS-CERT:

Google Security Team researchers Neel Mehta and Stephen Roettger have coordinated multiple vulnerabilities with CERT/CC concerning the Network Time Protocol (NTP). As NTP is widely used within operational Industrial Control Systems deployments, NCCIC/ICS-CERT is providing this information for US Critical Infrastructure asset owners and operators for awareness and to identify mitigations for affected devices. ICS-CERT may release updates as additional information becomes available.

These vulnerabilities could be exploited remotely. Exploits that target these vulnerabilities are publicly available.

Products using NTP service prior to NTP-4.2.8 are affected. No specific vendor is specified because this is an open source protocol.

iTunes 11.3.1

iTunes 11.3.1

Apple released iTunes 11.3.1

iTunes 11.3.1 addresses a problem where subscribed podcasts may stop updating with new episodes and resolves an issue where iTunes may become unresponsive while browsing your podcasts episodes in a list.

Mazda Infotainment System Version 29.00.000

According to Mazda Connect Customer Service, as of April 2014 the current version of Mazda Infotainment System 29.00.000 for 2014 Mazda3.

Mazda Infotainment System 29.00.000

Unconfirmed reports from Mazda Dealers version 30.00.000 might have been released as of May 2014.

It is not a good thing whenever the Infotainment System locks up.

Mazda3 Infotainment Center Blue Screen

iOS 7.1.1

iOS 7.1.1 for iPhone 5s

Apple release iOS 7.1.1 build 11D201 on Tuesday April 22, 2014.

iOS 7.1.1

This update contains improvements, bug fixes and security updates, including:

  • Further improvements to Touch ID fingerprint recognition
  • Fixes a bug that could impact keyboard responsiveness
  • Fixes an issue when using Bluetooth keyboards with VoiceOver enabled

For information on the security content of this update, please visit this website:  http://support.apple.com/kb/HT1222

iOS 7.1.1 is available via iTunes or Over The Air (OTA). On your iOS device, go to Settings > General > Software Update.

iOS 7.1.1

iOS 7.1.1 is available for the following iOS devices:

iPad:

  • iPad Air (Model A1474)
  • iPad Air (Model A1475)
  • iPad mini (Model A1489)
  • iPad mini (Model A1490)
  • iPad (4th generation Model A1458)
  • iPad (4th generation Model A1459)
  • iPad (4th generation Model A1460)
  • iPad mini (Model A1432)
  • iPad mini (Model A1454)
  • iPad mini (Model A1455)
  • iPad Wi-Fi 3rd generation
  • iPad Wi-Fi + Cellular (model for ATT)
  • iPad Wi-Fi + Cellular (model for Verizon)
  • iPad 2 Wi-Fi
  • iPad 2 Wi-Fi (Rev A)
  • iPad 2 Wi-Fi + 3G (GSM)
  • iPad 2 Wi-Fi + 3G (CDMA)

iPhone:

  • iPhone 5s (Model A1453, A1533)
  • iPhone 5s (Model A1457, A1518, A1528, A1530)
  • iPhone 5c (Model A1456, A1532)
  • iPhone 5c (Model A1507, A1516, A1526, A1529)
  • iPhone 5 (Model A1428)
  • iPhone 5 (Model A1429)
  • iPhone 4s
  • iPhone 4 (GSM)
  • iPhone 4 (GSM Rev A)
  • iPhone 4 (CDMA)

iPod touch:

  • iPod touch (5th generation)

WordPress 3.8.1 is now available

If you’re running a self-installed WordPress, you should be updating to WordPress 3.8.1.

WordPress 3.8.1 Update

From WordPress.org Blog:

Version 3.8.1 is a maintenance releases that addresses 31 bugs in 3.8, including various fixes and improvements for the new dashboard design and new themes admin screen. An issue with taxonomy queries in WP_Query was resolved. And if you’ve been frustrated by submit buttons that won’t do anything when you click on them (or thought you were going crazy, like some of us), we’ve found and fixed this “dead zone” on submit buttons.

WordPress 3.8.1