-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 APPLE-SA-2017-11-29-2 Security Update 2017-001 Security Update 2017-001 is now available and addresses the following: Directory Utility Available for: macOS High Sierra 10.13 and macOS High Sierra 10.13.1 Not impacted: macOS Sierra 10.12.6 and earlier Impact: An attacker may be able to bypass administrator authentication without supplying the administrator's password Description: A logic error existed in the validation of credentials. This was addressed with improved credential validation. CVE-2017-13872 Entry updated November 29, 2017 To confirm that your Mac has Security Update 2017-001: 1. Open the Terminal app, which is in the Utilities folder of your Applications folder. 2. Type "what /usr/libexec/opendirectoryd" and press Return. 3. If Security Update 2017-001 was installed successfully, you will see one of these project version numbers: opendirectoryd-483.1.5 on macOS High Sierra 10.13 opendirectoryd-483.20.7 on macOS High Sierra 10.13.1 If you require the root user account on your Mac, see https://support.apple.com/HT204012 for information on how to re-enable the root user and change the root user's password. Information will also be posted to the Apple Security Updates web site: https://support.apple.com/kb/HT201222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- iQJdBAEBCgBHFiEEcuX4rtoRe4X62yWlg6PvjDRstEYFAlofoispHHByb2R1Y3Qt c2VjdXJpdHktbm9yZXBseUBsaXN0cy5hcHBsZS5jb20ACgkQg6PvjDRstEarCRAA pbHH3yMF6yhH6uqAMVVSY3RNpV5hG3N2DCkNxNFq1be3qfbOmEs4oiYV7rGK8eGr blcaUmdZd7NVayQ5NW6ceQh3HuTBhY7/zYnidFnAGRKtQ3LTcVCwP8ayU94/NO36 E1ZQSqv6U0sQPLlyaNQ3gEko6zXp2lHcfI9l8hCCb+t8RpCAC4OUBSsqWoZIR4Gm xe7yi0NMYTvsMtN79eUz1ACbPCABHBkZqiOW8VGqSMdAMt/DgGjEJl0mjHe1jzoT DUCgXPi5N6VA5E/Y1sfx0WE+pJPBrAGK0ByLVBSPI+rP9PjYtVaJMMhYrwXdcK8G b9Q8ahalPrwD1wyob3Gtz0yFjc1b/0XmG/BkuR3DbOSAAz38bS6rG7O8UtUTbxPU Tx8CGYnadj2fPYGYPZw5kbm7Z2mqMq4nua49E4fuUDyPd1Tu5R85MgCnKs1ZvbPu /zCvWvGVJiOWVerATjkkYW3zm9RQeIs/MI3yU8eY8BOwMpSqtvsJhwaTGonP3+tL zft8eDtr9Ogu6pmo/XVmJIHfd8op9htqB5Pa9iiwnvmf9avuxuqRrg7C6jSRodkt LoCzBrvabpdVKf8RwtPTmdoa0PGURBPSpGqcv4qojPo6Llj4G1z9Fy52kU4o4JHC l59EGKk1652UKaQ+lE6X/Zl5wZ9Pv7/Gkftg1BFwtr4= =qhqE -----END PGP SIGNATURE-----