Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

About the security content of Xcode 11.5 (Apple releases a security update to address a vulnerability in Xcode)
Apple Support Site ^ | May 20, 2020 | Apple Support

Posted on 05/21/2020 10:08:13 AM PDT by dayglored

About the security content of Xcode 11.5

This document describes the security content of Xcode 11.5

About Apple security updates

For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available. Recent releases are listed on the Apple security updates page.

Apple security documents reference vulnerabilities by CVE-ID when possible.

For more information about security, see the Apple Product Security page.

Xcode 11.5

Released May 20, 2020

Git

Available for: macOS Catalina 10.15.2 and later

Impact: A crafted git URL that contains a newline in it may cause credential information to be provided for the wrong host

Description: This issue was addressed by forbidding a newline character in any value passed via the credential protocol.

CVE-2020-11008: Carlo Arenas


TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: apple; macos; xcode
Those of us using Xcode to develop Apple software should download the update ASAP.
1 posted on 05/21/2020 10:08:14 AM PDT by dayglored
[ Post Reply | Private Reply | View Replies]

To: Swordmaker

Apple *ping*


2 posted on 05/21/2020 10:08:45 AM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
Links from the article:

Apple security updates page

Apple Product Security page

3 posted on 05/21/2020 10:10:50 AM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Xcode...

If it were any better Apple wouldn’t give it to you,

If it were any worse, you wouldn’t use it.


4 posted on 05/21/2020 10:13:56 AM PDT by ImJustAnotherOkie (All I know is The I read in the papers.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ImJustAnotherOkie
> If it were any better Apple wouldn’t give it to you,

Now, now... Apple has been "giving away" operating system and software development software for decades.

In the case of Xcode, I presume it's what Apple uses internally anyway, so giving it away is an incentive for developers to work on Apple gear. They'd be insane to charge for it.

5 posted on 05/21/2020 10:17:25 AM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 4 | View Replies]

To: dayglored

Microsoft gives away Visual Studio now too. I always liked it better than Xcode anyway.

Then again it may have been Objective-C that I really didn’t like.

Objective-C could make a rose smell like a turd.


6 posted on 05/21/2020 10:53:09 AM PDT by ImJustAnotherOkie (All I know is The I read in the papers.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: ImJustAnotherOkie
> Then again it may have been Objective-C that I really didn’t like. Objective-C could make a rose smell like a turd.

I've never much cottoned to these newfangled languages. They make it so you can hardly do anything interesting or dangerous. It's like trying to do fine technical work with a pair of kindergarten scissors with the rounded points.

I learned to program in FORTRAN, picked up a handful of ASM for small computers, and some years later I fell in love with K&R C (ANSI C is okay). Every language after that has been a cascading flood of well-meaning but annoying crap.

Besides, a Real Programmer can write FORTRAN code in -any- language, right? :-)

7 posted on 05/21/2020 3:58:01 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 6 | View Replies]

To: dayglored

Objective C was really strange. Most calls need to be preceded by a memory allocation.


8 posted on 05/21/2020 4:27:48 PM PDT by ImJustAnotherOkie (All I know is The I read in the papers.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: dayglored

I learned 8-10 hard core languages over the years plus a dozen scripting languages.

If you want to see a bullshit tool look at Mendix.

Python is probably the best thought out tool.

WPF was my biggest challenge. But makes a great UI.


9 posted on 05/21/2020 4:38:25 PM PDT by ImJustAnotherOkie (All I know is The I read in the papers.)
[ Post Reply | Private Reply | To 7 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson