{"id":1647,"date":"2010-03-29T20:11:37","date_gmt":"2010-03-29T18:11:37","guid":{"rendered":"http:\/\/daniel.haxx.se\/blog\/?p=1647"},"modified":"2023-03-29T15:58:12","modified_gmt":"2023-03-29T13:58:12","slug":"apple-only-391-days-behind","status":"publish","type":"post","link":"https:\/\/daniel.haxx.se\/blog\/2010\/03\/29\/apple-only-391-days-behind\/","title":{"rendered":"Apple &#8211; only 391 days behind"},"content":{"rendered":"\n<p>In the <a href=\"https:\/\/curl.se\/\">curl project<\/a>, we take security seriously. We work hard to make sure we don&#8217;t open up for <a href=\"https:\/\/curl.se\/docs\/security.html\">security problems<\/a> of any kind and once we fail, we work hard at analyzing the problem and coming up with a proper fix as swiftly as possible to make our &#8220;customer&#8221; as little vulnerable as possible.<\/p>\n\n\n\n<p>Recently I&#8217;ve been surprised and slightly shocked by the fact that a lot of open source operating systems didn&#8217;t release any security upgrades to our <a href=\"http:\/\/curl.haxx.se\/docs\/adv_20100209.html\">most recent security flaw<\/a> until well over a month after we first <a href=\"http:\/\/curl.haxx.se\/docs\/adv_20100209.html\">publicized the flaw<\/a>. I&#8217;m not sure why they all reacted so slowly. Possibly it is because <a href=\"http:\/\/en.wikipedia.org\/wiki\/Vendor-sec\">vendor-sec<\/a> isn&#8217;t quite working as they were informed prior to the notification, and of course I don&#8217;t really expect many security guys to be subscribed to the <a href=\"http:\/\/curl.haxx.se\/mail\/\">curl mailing lists<\/a>. Slow distros include <a href=\"http:\/\/www.linuxsecurity.com\/content\/view\/152006?rdf\">Debian<\/a> and <a href=\"http:\/\/www.linuxsecurity.com\/content\/view\/151945\/\">Mandriva<\/a> while <a href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=563220\">Redhat did great<\/a>.<\/p>\n\n\n\n<p>Today however, I got a mail from Apple (and no, I don&#8217;t know why they send these mails to me but I guess they think I need them or something) with the subject &#8220;<em>APPLE-SA-2010-03-29-1 Security Update 2010-002 \/ Mac OS X v10.6.3<\/em>&#8220;. Aha! Did Apple now also finally update their curl version you might think?<\/p>\n\n\n\n<p>They did. But they did not fix this problem. They fixed two previous problems universally known as <a href=\"http:\/\/curl.haxx.se\/docs\/adv_20090303.html\">CVE-2009-0037<\/a> and <a href=\"http:\/\/curl.haxx.se\/docs\/adv_20090812.html\">CVE-2009-2417<\/a>. Look at the date of that first one. March 3, <strong>2009<\/strong>. Yes, a whopping <em>391 days after the problem<\/em> was first made public, Apple sends out the security update. Cool. At least they eventually fixed the problem&#8230;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In the curl project, we take security seriously. We work hard to make sure we don&#8217;t open up for security problems of any kind and once we fail, we work hard at analyzing the problem and coming up with a proper fix as swiftly as possible to make our &#8220;customer&#8221; as little vulnerable as possible. &hellip; <a href=\"https:\/\/daniel.haxx.se\/blog\/2010\/03\/29\/apple-only-391-days-behind\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Apple &#8211; only 391 days behind<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":5,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7,133],"tags":[273,33,428],"class_list":["post-1647","post","type-post","status-publish","format-standard","hentry","category-curl","category-security","tag-apple","tag-curl-and-libcurl","tag-security"],"_links":{"self":[{"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/posts\/1647","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/comments?post=1647"}],"version-history":[{"count":8,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/posts\/1647\/revisions"}],"predecessor-version":[{"id":22206,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/posts\/1647\/revisions\/22206"}],"wp:attachment":[{"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/media?parent=1647"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/categories?post=1647"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/tags?post=1647"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}