Date: 30 August 2007
References: ESB-2007.0261 ESB-2007.0446
Click here for printable version
Click here for PGP verifiable version
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2007.0657 -- [Appliance]
AirPort Extreme Base Station Firmware version 7.2.1
30 August 2007
===========================================================================
AusCERT Security Bulletin Summary
---------------------------------
Product: AirPort Extreme 802.11n* base stations
Publisher: Apple
Operating System: Network Appliance
Impact: Denial of Service
Access: Remote/Unauthenticated
CVE Names: CVE-2007-2242
Ref: ESB-2007.0446
ESB-2007.0261
Original Bulletin: http://docs.info.apple.com/article.html?artnum=61798
- --------------------------BEGIN INCLUDED TEXT--------------------
- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
APPLE-SA-2007-08-29 Firmware version 7.2.1 for
AirPort Extreme 802.11n* base stations
Firmware version 7.2.1 is now available for AirPort Extreme 802.11n*
base stations. (* Based on an IEEE 802.11n draft specification)
Further information on the base station is available via:
http://www.apple.com/airportextreme/
Firmware version 7.2.1 fixes the following security issue:
AirPort Extreme Base Station with 802.11n*
CVE-ID: CVE-2007-2242
Available for: AirPort Extreme Base Station with 802.11n*
Impact: Remote attackers may be able to adversely affect network
performance
Description: A design issue exists in the IPv6 protocol's handling
of type 0 routing headers. Depending on network topology and
capacity, the reception of specially crafted IPv6 packets may lead to
a reduction in network bandwidth. This update addresses the issue by
disabling the support for type 0 routing headers. This issue does not
affect the Gigabit Ethernet version of AirPort Extreme Base Station
with 802.11n*.
Installation note for Firmware version 7.2.1
Firmware version 7.2.1 is installed into an AirPort Extreme Base
Station with 802.11n* by running the AirPort Utility which is
provided with the Base Station.
Information will also be posted to the Apple Security Updates
web site:
http://docs.info.apple.com/article.html?artnum=61798
This message is signed with Apple's Product Security PGP key,
and details are available at:
http://www.apple.com/support/security/pgp/
- -----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.0.6 (Build 6060)
iQEVAwUBRtXM7MgAoqu4Rp5tAQgZ1gf/aPB1d1u6oL9X90fXS3Y9Uwv+/EdaPFNg
9Sd3mv1L2g7/UjXHLF7T6mjGmx303h3nYRX5LvZpU8tfB4t59X67IPjOfp/xkF77
sPgMv2s1eYeLXnKgNd+pCukVcVyeucHqDIo0qDcUukmkVouXFyYMOpD9DhqdgYre
I4ePirMHt+FBHZ5Vz+DZBZtIYTtD5XJY3G14XEYWSMHCNZypTpYxnuweoYP43mt5
MpesCELJE9zotgKKhsTEqaguipFP4z/gqtiRgnxbAeRT3mjc/RnsT4n2u1EBLqBN
3dHwv8mKFbrMIbiPqCDQeZU21bAtdRQNpswc+u+WkDetsS+W0b1Mlg==
=UChZ
- -----END PGP SIGNATURE-----
- --------------------------END INCLUDED TEXT--------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members. As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release of the security bulletin. It may
not be updated when updates to the original are made. If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.
Contact information for the authors of the original document is included
in the Security Bulletin above. If you have any questions or need further
information, please contact them directly.
Previous advisories and external security bulletins can be retrieved from:
http://www.auscert.org.au/render.html?cid=1980
If you believe that your computer system has been compromised or attacked in
any way, we encourage you to let us know by completing the secure National IT
Incident Reporting Form at:
http://www.auscert.org.au/render.html?it=3192
===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072
Internet Email: auscert@auscert.org.au
Facsimile: (07) 3365 7031
Telephone: (07) 3365 4417 (International: +61 7 3365 4417)
AusCERT personnel answer during Queensland business hours
which are GMT+10:00 (AEST).
On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967
iQCVAwUBRtZARyh9+71yA2DNAQL5rgP+NvNyYFmjS70Bdswq+9JCaFTdY+ioQiPD
8chd3anCQEZZnrjX+zqv9tSGRENS6nvgdNiqCK1ygpkxdwensSQ5o94IBulWsIFh
xYSXPI3Pl6OgKHpTLK9Xe4pHz0YCUqEcrwBKwCRf06PoHCd+VcJHLEy7Q7Z2LWE6
hlRDicbBxJk=
=hUZ3
-----END PGP SIGNATURE-----
|