<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Spam Chronicles&#187; apple_tv</title>
	<atom:link href="http://www.spamchronicles.com/tag/apple_tv/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.spamchronicles.com</link>
	<description>Chronicling My Spam Explorations</description>
	<lastBuildDate>Wed, 12 Sep 2007 02:11:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Apple TV Security Update</title>
		<link>http://www.spamchronicles.com/2007/06/20/apple-tv-security-update/</link>
		<comments>http://www.spamchronicles.com/2007/06/20/apple-tv-security-update/#comments</comments>
		<pubDate>Wed, 20 Jun 2007 20:06:48 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[apple_tv]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/apple-tv-security-update/</guid>
		<description><![CDATA[Apple has released their first security update for Apple TV. According the bulletin a remote attacker can cause a denial of service attack or arbitrary code execution. This patches the same flaw that was plugged in OS X last month. At first I thought this was interesting but probably not a problem. Apple TV&#8217;s seem [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/appletvthumbnail.jpg" alt="Apple TV (Small)" align="left" /><b>Apple</b> has released their first security update for <b>Apple TV</b>. According <a href="http://docs.info.apple.com/article.html?artnum=305631" title="JUmp to the Apple bulletin">the bulletin</a> a remote attacker can cause a denial of service attack or arbitrary code execution.</p>
<p>This patches the same flaw that was <a href="http://www.spamchronicles.com/security-vulnerability/security-update-2007-05-for-mac-os-x/" title="Jump to my post about last month's OS X update">plugged in OS X last month</a>.</p>
<p>At first I thought this was interesting but probably not a problem. Apple TV&#8217;s seem limited in what they can do plus they usually reside on a home network behind a NAT router. Apparently this isn&#8217;t entirely true and will become even less true as features such as viewing YouTube videos and (maybe) movie rentals are added to Apple TV. Plus the vulnerability exists in UPnP IDG (Universal Plug &#8216;n Play Internet Device Gateway) which is used by many NAT routers to enable devices like Apple TV to get on the Internet. At least one security researcher was quoted as saying <a href="http://www.theregister.co.uk/2007/06/20/critical_appletv_patch/" title="JUmp to The Register article about the update">this is a serious flaw</a>.</p>
<p>The update is only available through Apple TV&#8217;s self-update feature. Apple TV checks for updates on a weekly schedule so it may be up to a week before it receives the update. You can also manually trigger the update by selecting <b>Settings</b> -&gt; <b>Update Software</b> from the menu.</p>
<p>After applying the update the software version will be <b>1.1</b>. You can check the version by selecting <b>Settings</b> -&gt; <b>About</b> from the menu.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/06/23/security-update-2007-006-for-apple-os-x/" rel="bookmark" class="crp_title">Security Update 2007-006 for Apple OS X</a></li><li><a href="http://www.spamchronicles.com/2007/07/11/apple-adds-to-patch-tuesday/" rel="bookmark" class="crp_title">Apple Adds to Patch Tuesday</a></li><li><a href="http://www.spamchronicles.com/2007/05/30/quicktime-security-update1/" rel="bookmark" class="crp_title">Quicktime Security Update</a></li><li><a href="http://www.spamchronicles.com/2007/05/25/security-update-2007-05-for-mac-os-x/" rel="bookmark" class="crp_title">Security Update 2007-05 for Mac OS X</a></li><li><a href="http://www.spamchronicles.com/2007/06/21/apple-releases-10410-for-os-x/" rel="bookmark" class="crp_title">Apple Releases 10.4.10 for OS X</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/06/20/apple-tv-security-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
