[Ii2-announce] i-Installer 2.82 released. Security release: all users requested to upgrade

Gerben Wierda Gerben.Wierda at rna.nl
Wed Oct 11 01:14:53 CEST 2006


I have noticed that the setup of i-Installer brings with it a  
potential security issue which is also potentially serious. This find  
(by myself, luckily) is not a happy event for me.

I have patched i-Installer. As a result, installing i-Installer with  
drag-and-drop from the II2.dmg volume is now deprecated. The II2.dmg  
now contains an Apple Installer.app package which installs i- 
Installer. Also, upgrading with the i-Installer i-Package is supported.

i-Installer itself now contains some basic checks for this security  
issue.

All i-Packages will be upgraded/released shortly and they will all  
contain a check for i-Installer version 2.82 or up to force users to  
upgrade.

The issue is serious enough for me to speed the release of many i- 
Packages I have been working on and to kill all older releases of i- 
Installer  from the .dmg repository.

As a result of the speed up of the releases, there is no testing  
period for those i-Packages and I therefore expect that there will be  
more problem/bug reports than usual. My apologies beforehand.

G 


More information about the Ii2-announce mailing list