Stupid is as stupid does
MS has been condemned pretty harshly for including security fixes in big honking massive packs that have to be tested thoroughly because you never know what the hell they're going to break... as they should be. Apple's been pretty good about it, when a security exploit has been found in a BSD part of the OS they've generally issued a nice tiny lil patch to apply.
...then along comes 10.2.8, which is a fubar upgrade, royally hosing a bunch of people's machines, to the point where Apple had to pull the patch. The problem? The patch has two security fixes that are needed (ssh & sendmail)! I can only guess Apple thought they were "close" with 10.2.8, and instead of releasing the security fixes decided to "roll them in".
With all the hell MS is getting lately, and this being one of the things MS has been beaten up on pretty badly, it was just plain stupid for Apple to do this. There are still no patches available for those the exploits more than a week later (well, you can compile your own), but luckily with freeBSD the exploit can't execute code with root priveledges... will just crash sshd, which, depending on the situation, could pretty much suck.
Egh. Stupid is as stupid does.

Posted by drunkenbatman





