Comments (4)
I already committed the new Sparkle version in master and 1.4beta1 shipped with Sparkle 1.13.1 as will 1.4.
Thanks for reporting, it's a serious issue 👍
I'll close this issue when I've shipped a stable release with the updated Sparkle.
from keepingyouawake.
Although the Sparkle.framework version is older, KeepingYouAwake uses https for it’s update, so it’ should not be vulnerable to this issue.
-Al-
On Tue, Feb 09, 2016 at 03:18 PM, Kevin S wrote:
A critical MITM vulnerability has been disclosed in the Sparkle framework:
http://arstechnica.com/security/2016/02/huge-number-of-mac-apps-vulnerable-to-hijacking-and-a-fix-is-elusive/ http://arstechnica.com/security/2016/02/huge-number-of-mac-apps-vulnerable-to-hijacking-and-a-fix-is-elusive/
A fix has been released as of version 1.13.1. KeepingYouAwake was one of the few apps on my system flagged for using an older version.
https://github.com/sparkle-project/Sparkle/releases/tag/1.13.1 https://github.com/sparkle-project/Sparkle/releases/tag/1.13.1
I would be extremely please to see this resolved quckly.
from keepingyouawake.
Sorry, I was looking at v1.22b1 which used https, but for whatever reason I see that v1.3.1 did not. So looks like I need to update to v1.4b1 immediately.
-Al-
On Wed, Feb 10, 2016 at 12:00 AM, Al Varnell wrote:
Although the Sparkle.framework version is older, KeepingYouAwake uses https for it’s update, so it’ should not be vulnerable to this issue.
-Al-
On Tue, Feb 09, 2016 at 03:18 PM, Kevin S wrote:
A critical MITM vulnerability has been disclosed in the Sparkle framework:
http://arstechnica.com/security/2016/02/huge-number-of-mac-apps-vulnerable-to-hijacking-and-a-fix-is-elusive/ http://arstechnica.com/security/2016/02/huge-number-of-mac-apps-vulnerable-to-hijacking-and-a-fix-is-elusive/
A fix has been released as of version 1.13.1. KeepingYouAwake was one of the few apps on my system flagged for using an older version.
https://github.com/sparkle-project/Sparkle/releases/tag/1.13.1 https://github.com/sparkle-project/Sparkle/releases/tag/1.13.1
I would be extremely please to see this resolved quckly.
from keepingyouawake.
I suggest closing this ticket since KYA version 1.4.0 includes Sparkle 1.14.0
from keepingyouawake.
Related Issues (20)
- allow display to sleep vs locking HOT 2
- The app stops working some times HOT 6
- Option "Indefinitely" cannot be deleted in Settings. HOT 3
- Creating a schedule HOT 1
- [Suggestion] Keyboard Shortcut HOT 4
- Not working in macOS Ventura? HOT 1
- Display the time that remains until the activation duration is elapsed
- Activate URI schemes doesn't work anymore HOT 6
- Doesn't work on OSX Ventura HOT 10
- command line parameters with duration don't seem to work HOT 2
- When I unlock the machine It switches back to the default state!
- Update check on start
- External display advanced option spams caffeinate processes HOT 1
- Bug: Theme does not switch while active HOT 1
- does not work when the lid is close : lock screen is opened (ventura) HOT 2
- When "allow the display to sleep" is enabled, Lock Screen then won't stay on!
- does not stay awake HOT 1
- Activate when connected to external display doesn’t work for mirroring mode
- KeepingYouAwake disables itself sometimes
- Downloader differs from previously opened versions HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from keepingyouawake.