Apple has today reissued a previously released Security Update. The update is around 13MB in size.
Apple has included a method to check whether the update is official using SHA-1 digest.
This document discribes how to verify the a SHA-1 digest (also known as a checksum).
To verify a software update from Apple, which contains a SHA-1 digest, perform the following steps.
Important: Verifying the SHA-1 of a software update is optional, it is being provided on Apple software updates for those individuals who want to verify the authenticity of an update.
- 1. Open Terminal.
- 2. Type the following at the terminal prompt: /usr/bin/openssl sha1 [full path to file]
Example: /usr/bin/openssl sha1 /Users/test/Documents/1024SecUpd2003-03-03.dmg
The SHA-1 digest is displayed as: sha1 ([full path to the file])= [checksum amount]
Example: SHA1(/Users/test/Documents/1024SecUpd2003-03-03.dmg) =2eb722f340d4e57aa79bb5422b94d556888cbf38
Apple has stated the following about the update itself:
Security Update 2006-002 is recommended for all users and improves the reliability and security of the following components:
apache_mod_php
CoreTypes
LaunchServices
Mail
rsync
Safari
Additionally, this update incorporates Security Update 2006-001, which improves the security of the following components:
apache_mod_php
automount
Bom
Directory Services
iChat
IPSec
LaunchServices
LibSystem
loginwindow
Mail
rsync
Safari
Syndication
SHA1 for SecUpd2006-002Ti.dmg=
39a36533b1fa33ed742e7cca07f120be8d7e292f