Archived - About the security content of AirPort Base Station Update 2010-001
This document describes the security content of AirPort Base Station Update 2010-001.
For the protection of our customers, Apple does not disclose, discuss, or confirm security issues until a full investigation has occurred and any necessary patches or releases are available. To learn more about Apple Product Security, see the Apple Product Security website.
For information about the Apple Product Security PGP Key, see "How to use the Apple Product Security PGP Key."
Where possible, CVE IDs are used to reference the vulnerabilities for further information.
To learn about other Security Updates, see "Apple Security Updates."
- CVE-ID: CVE-2009-2822
Available for: Mac OS X v10.5.7 or later, Windows 7, Vista, XP
Impact: An unauthorized user may be able to connect to a restricted network that uses a network extender
Description: An AirPort administrator may restrict access to a network by specifying a MAC address ACL. There is an issue where MAC address ACLs are not properly propagated to network extenders. This can allow an unauthorized user to access a network that should be restricted via the MAC address ACL. This update addresses the issue through improved distribution of settings to network extenders. Credit to Guido Lamberty for reporting this issue.