lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-id: <BCD82780-1150-4A3B-9B1D-097E9D16BE3A@lists.apple.com>
Date: Mon, 08 Jan 2018 10:26:45 -0800
From: Apple Product Security <product-security-noreply@...ts.apple.com>
To: security-announce@...ts.apple.com
Subject: [FD] APPLE-SA-2018-1-8-1 iOS 11.2.2

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

APPLE-SA-2018-1-8-1 iOS 11.2.2

iOS 11.2.2 is now available and and addresses the following:

Available for: iPhone 5s and later, iPad Air and later, and iPod
touch 6th generation
Description: iOS 11.2.2 includes security improvements to Safari and
WebKit to mitigate the effects of Spectre (CVE-2017-5753 and
CVE-2017-5715).

We would like to acknowledge Jann Horn of Google Project Zero; and
Paul Kocher in collaboration with Daniel Genkin of University of
Pennsylvania and University of Maryland, Daniel Gruss of Graz
University of Technology, Werner Haas of Cyberus Technology,
Mike Hamburg of Rambus (Cryptography Research Division),
Moritz Lipp of Graz University of Technology, Stefan Mangard of
Graz University of Technology, Thomas Prescher of Cyberus Technology,
Michael Schwarz of Graz University of Technology, and Yuval Yarom of
University of Adelaide and Data61 for their assistance.

Installation note:

This update is available through iTunes and Software Update on your
iOS device, and will not appear in your computer's Software Update
application, or in the Apple Downloads site. Make sure you have an
Internet connection and have installed the latest version of iTunes
from https://www.apple.com/itunes/

iTunes and Software Update on the device will automatically check
Apple's update server on its weekly schedule. When an update is
detected, it is downloaded and the option to be installed is
presented to the user when the iOS device is docked. We recommend
applying the update immediately if possible. Selecting Don't Install
will present the option the next time you connect your iOS device.

The automatic update process may take up to a week depending on the
day that iTunes or the device checks for updates. You may manually
obtain the update via the Check for Updates button within iTunes, or
the Software Update on your device.

To check that the iPhone, iPod touch, or iPad has been updated:

* Navigate to Settings
* Select General
* Select About. The version after applying this update
will be "11.2.2".

Information will also be posted to the Apple Security Updates
web site: https://support.apple.com/kb/HT201222

This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/
-----BEGIN PGP SIGNATURE-----

iQJdBAEBCgBHFiEEcuX4rtoRe4X62yWlg6PvjDRstEYFAlpTsD4pHHByb2R1Y3Qt
c2VjdXJpdHktbm9yZXBseUBsaXN0cy5hcHBsZS5jb20ACgkQg6PvjDRstEYUpxAA
vCQLuvB8TKprME67s99DpRR7wjmM8i6fQvFUEN9J6+hWaBXB2qUYV/O8R8QLUJwe
in/su6SgDtqOXLVYwMreJimbJjythyNZykuz11tkFT+8keo2JJZDjVtSbF+wRkC2
pOqVUZWQ7uvxNOkNky48zzxSGV8qgGOIAcyOZT2U7A/q4v5wWu1I6YozarxuAb6E
kyhhHqXlC5WHgt1EeVFVG9vTKYBwOGZHQyDSI6D41FI0Klc27L1Ua8t/inBMyqDp
zqD8U1KX6kNKVbLHJujr+My2EV3GgNJ1lk8FvoMcQrsVWgZaoooFYHS/uA4zIs2Z
DuiljCxfLodw0/7pDkDAkIrCiGtX0ywl6m8yMu/poruT/hf+aDcpgT8tzpT0lw87
t8LB4ThYVn6efOMrzMWOKcvlScCCzMkPouwm2h5Vz3z/WSKDziYl9e5zv4jraK89
Lp+tpkfKoAKcqxHomoxO2k6Gk3Q/Irlm/+ar3KGO0J2hGe3S2oNvwquOAiYZzQMc
EVEjK0HOxZy2x/TUGNUgCobjJkLmIIB8CxwEI2fO31O8WZ0RJluyBJVjlyG6siCP
oQX6Nx0nA8XefLqJnVgKhzornjoHYgoiM+dVt0uIzuW+AWULB3CR5uuMsCz06Tnv
7UTqjyev4H289HkIMRuD5SsE7KVlm/3L/zYzxPZoryU=
=48wl
-----END PGP SIGNATURE-----


_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ