About the security content of AirPort Base Station Update 2010-001

This document describes the security content of AirPort Base Station Update 2010-001.

For the protection of our customers, Apple does not disclose, discuss or confirm security issues until a full investigation has occurred and any necessary patches or releases are available. To find out more about Apple Product Security, see the Apple Product Security website.

For information about the Apple Product Security PGP Key, see "How to use the Apple Product Security PGP Key."

Where possible, CVE IDs are used to reference the vulnerabilities for further information.

To find out more about other Security Updates, see "Apple Security Updates".

CVE-ID: CVE-2009-2822

Available for: Mac OS X v10.5.7 or later, Windows 7, Vista, XP

Impact: an unauthorised user may be able to connect to a restricted network that uses a network extender

Description: an AirPort administrator may restrict access to a network by specifying a MAC address ACL. There is an issue where MAC address ACLs are not propagated to network extenders properly. This can allow an unauthorised user to access a network that should be restricted via the MAC address ACL. This update addresses the issue through improved distribution of settings to network extenders. Credit to Guido Lamberty for reporting this issue.

Important: Information about products not manufactured by Apple is provided for information purposes only and does not constitute Apple’s recommendation or endorsement. Please contact the vendor for additional information.

Published Date: