May 2, 2024

Apple Updates AirPort Extreme and Time Capsule With Heartbleed Fix

Posted April 22, 2014 at 11:03pm by iClarified · 9743 views
Apple has released a firmware update for the AirPort Extreme and Time Capsule Base Stations that addresses the Heartbleed security vulnerability.

Firmware update 7.7.3 is recommended for all AirPort Extreme and AirPort Time Capsule base stations with 802.11ac. It provides security improvements related to SSL/TLS. Other AirPort base stations do not require this firmware update.

AirPort Base Station Firmware Update 7.7.3
Available for: AirPort Extreme and AirPort Time Capsule base stations with 802.11ac

Impact: An attacker in a privileged network position may obtain memory contents

Description: An out-of-bounds read issue existed in the OpenSSL library when handling TLS heartbeat extension packets. An attacker in a privileged network position could obtain information from process memory. This issue was addressed through additional bounds checking. Only AirPort Extreme and AirPort Time Capsule base stations with 802.11ac are affected, and only if they have Back to My Mac or Send Diagnostics enabled. Other AirPort base stations are not impacted by this issue.

How to download and install a firmware update?
1. Make sure you are connected to the Internet.
2. Open AirPort Utility. (Navigate to the /Applications/Utilities folder, to locate it.) AirPort Utility will display a badge to the right of the name of any AirPort base station in your network that has a firmware update available for it.
3. Select the AirPort base station you want to update.
4. Click the Update button.

Read More