Morning folks. There is an "Airport Base Station & Time Capsule” update available.
Apple today released AirPort Base Station Firmware Update 7.9.1 firmware update to close a handful of security holes related to remote hacks, memory leaks and user data deletion and is recommended for all AirPort Extreme and AirPort Time Capsule base stations with 802.11ac.
Among the resolved security issues is a bug that allowed a remote attacker to leak memory through an errant out-of-bounds read capability.
Three denial of service issues were addressed in the patch, two of which could be triggered remotely through faulty code. The third involved a similar denial of service attack carried out by a bad actor in a privileged position. The problems were resolved through improved input validation and memory handling.
A null pointer dereference and a "use after free" issue were cited in a remote attack that could enabled a hacker to run code on a targeted device, while a separate issue allowed source-routed IPv4 packets to be unexpectedly accepted.
Finally, the update addresses an issue that left some some user information on a base station after performing a factory reset.
Your mission, should you choose to accept it…. Is to update this device:
- Ensure that Time Machine is not backing up, if it is, wait till it finishes
- GoTo: Applications > Utilities and fire up your Airport Utility app
- Left click on the AirPort Time Capsule
- Left click on the Update button to the right of the version number
- A warning message may pop up saying; “Server is shutting down” just click the OK button
- Following the instructions and let it do its thing
- When the update is finished and the AirPort Time Capsule has restarted, a green dot will appear
- Quit Airport Utility
- All good to go again
As always, should you or any of your devices fail to work or explode, I will disavow any knowledge of your actions. This post may self-destruct. Good luck Cheers 🍷
EDIT: added more update detail
#
