On TV.com: Jessica Alba photos
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Apr 21, 2006 11:35:00 PM

Apple Computer is investigating several unpatched and potentially serious security flaws in Mac OS X that have been publicly disclosed, the company said Friday.

Tom Ferris, a security researcher in Mission Viejo, Calif., published late on Thursday information on seven flaws in Apple's operating system that potentially put Mac users at risk of a cyberattack. The most serious of the flaws could let attackers surreptitiously run malicious code on users' PCs, Ferris said in an interview via instant messaging.

"We're in the process of investigating and addressing them," Bud Tribble, Apple's vice president of software technology, told CNET News.com. "I think it is important to note that although these are potential vulnerabilities, there are no known exploits to them and they are not affecting customers today."

Five of the flaws identified by Ferris relate to how Mac OS handles various image file formats--including BMP, TIFF and GIF, according to his security advisories. Another flaw involves the way OS X decompresses Zip archives. Additionally, Ferris claims to have found several bugs in Apple's Safari browser.

"The image flaws are the scariest ones, giving an attacker multiple methods of compromising a host," Ferris said. "They can be exploited to execute arbitrary code very easily and were not hard to find."

Apple silently fixed one of the flaws related to the handling of TIFF image files in update 10.4.6, Ferris said. The other bugs remain unpatched, he said, adding that he reported the issues to Apple earlier this year.

Apple believes the public disclosure of security flaws doesn't help anyone, a position shared by most software makers. "We don't feel that our customers are better served by public disclosure of potential issues," Tribble said. "We think that in the general case, people who need to know about issues are the ones that can actually fix the bugs."

Ferris in the past has released information on flaws in several Apple products, including iTunes and QuickTime, as well as the Firefox Web browser, before an official patch was made available.

Security monitoring companies Secunia and the French Security Incident Response Team, or FrSIRT, deem the latest Mac OS X issues "highly critical" and "critical," respectively.

"Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by attackers to execute arbitrary commands or cause a denial of service," Secunia said in an advisory. To protect against attacks, the company recommends not surfing to untrusted Web sites and not opening suspect Zip archives or images.

Apple expects to address the issues in an upcoming security update but could not say when that fix might be released. "Our target is to do it promptly," Tribble said. "How quickly that can be done depends on a lot of variables, in terms of how much information we get and how complex the things are to address."

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 92 Talkback(s)
Thanks !
As a Mac User, I appreciate the plug !

"'cause they will be happy to tell you that your machine is now
only half or even one quarter as fast as theirs. For about the
same cash."

... (Read the rest)
Posted by: Jkirk3279 Posted on: 04/26/06 You are currently: a Guest | | Terms of Use
Hmm, sounds familiar  georgeou | 04/21/06
Very familiar  zkiwi | 04/21/06
No, balanced reporting  mdemuth | 04/21/06
One more time...  gfeier | 04/21/06
Deep  ITTech001 | 04/21/06
Shallow...  gfeier | 04/21/06
Agree with ITTech001  b.d.hi | 04/22/06
Message has been deleted.  SouthernPride | 04/22/06
the most dangerous thing about Windows...  mdsmedia | 04/22/06
You MAC users are just as vulnerable as Windows users  IronCladChicken | 04/22/06
Respectfully, I disagree...  RicD_ | 04/22/06
Doesn't affect me.  nomorems | 04/23/06
One more time...  ye | 04/22/06
Lucky you  zkiwi | 04/22/06
I know my systems...  ye | 04/23/06
Yeah...  Jim Blaine - Bellingham WA. | 04/23/06
Re: One more time...  dvm | 04/24/06
I'm sure there are a few people still using a Packard Bell Computer System  Laff | 04/24/06
I think you miss my point  zkiwi | 04/22/06
I didn't mention either of these things in a blog  georgeou | 04/21/06
Apparently not  zkiwi | 04/22/06
Of course he did, you just took the hook, line and sinker.  No_Ax_to_Grind | 04/23/06
Really?  zkiwi | 04/24/06
You also didn't mention...  tic swayback | 04/23/06
So what?  NonZealot | 04/23/06
Oops, one more thing  NonZealot | 04/23/06
Who's squirming.... I for one am already on record as  Laff | 04/24/06
Finally, someone makes sense...  FatherJ | 04/24/06
Interesting attitude  tic swayback | 04/24/06
tic, you should be thanking George  NonZealot | 04/24/06
Maybe you're right  tic swayback | 04/24/06
Thanks tic!  NonZealot | 04/24/06
You've let MS slide for far too long. Is it too late?  tic swayback | 04/24/06
ZDNet talkbacks sure prove your point!!  NonZealot | 04/24/06
You're not looking in the right place  tic swayback | 04/24/06
Game, set, match: you win tic  NonZealot | 04/24/06
Why I'm here  tic swayback | 04/24/06
interesting...........  deadmanjoe | 04/21/06
... silence ...  palmwarrior | 04/22/06
Bad transition...  palmwarrior | 04/22/06
Because the flaws are not critical?  Mikael_z | 04/22/06
Stuff it  I'm Ye, the MS SHILL . | 04/23/06
Here we go again  b.d.hi | 04/22/06
the most dangerous thing about Windows...  mdsmedia | 04/22/06
Which is it? None, or thousands?  IronCladChicken | 04/22/06
One more time for the MS propaganda shill team:  nomorems | 04/23/06
"Superior" G5? Tell it to the Macintel folks...  ajole | 04/24/06
Thanks !  Jkirk3279 | 04/26/06
Message has been deleted.  SouthernPride | 04/22/06
You need to replace that keyboard  zmud | 04/22/06
Message has been deleted.  SouthernPride | 04/22/06
Serious question...  bidemytime | 04/22/06
page views versus real news  Steven Rogers | 04/22/06
I agree with your ads per page hit comment.  nomorems | 04/23/06
There are ads here?  Colonel Panijk | 04/24/06
I'm sorry but I missed the sensationalism in this article  palmwarrior | 04/22/06
You missed even more  bidemytime | 04/22/06
I've had a tough month and I'm task switching between too many things...  palmwarrior | 04/22/06
Somewhat serious answer...  Tony Agudo | 04/22/06
Darn it! ZDNet screwed up my links!  Tony Agudo | 04/22/06
Maybe that's not his job?  FatherJ | 04/24/06
You must be new here  bidemytime | 04/24/06
Kinda off topic, BUT, will STEVE wanna SUE about this?  Feldwebel Wolfenstool | 04/22/06
"Off Topic" heh heh heh...that should be your name  Laff | 04/24/06
Don't use Windows, it is full of flaw$$$  NonZealot | 04/23/06
thanks!  Reverend MacFellow | 04/24/06
9.5, nice work!  ajole | 04/24/06
Here's why it poses no risk to Mac users  Boot_Agnostic | 04/23/06
We shall see....I'm just waiting for the "IS" a problem report.  Laff | 04/23/06
Ou 2 U  Reverend MacFellow | 04/24/06
Who were you post hijacking  Boot_Agnostic | 04/24/06
S W E E T  Boot_Agnostic | 04/25/06
Message has been deleted.  SouthernPride | 04/23/06
Hey!  Jim Blaine - Bellingham WA. | 04/23/06
I wonder...  Laff | 04/23/06
The Macintosh really seems to be some sort of threat to you...  BitTwiddler | 04/24/06
Excellent point.....he sort of reminds be of the plains buffalo  Laff | 04/24/06
Ou-wee!  Reverend MacFellow | 04/24/06
Patch all you want, Macheads.  Mr. Roboto | 04/23/06
Most of your statement is right on.......then you go  Laff | 04/24/06
I'm in the buisness of computer support.  IronCladChicken | 04/25/06
And I would agree but I would NOT use the word  Laff | 04/25/06
Actually, Mac almost has a patch for the wetware...  ajole | 04/24/06
Frankly, if I were a script kiddy or a really good hacker  IronCladChicken | 04/25/06
Could, might, maybe, ......  Reverend MacFellow | 04/24/06
RIGHT ON!!!!  Laff | 04/24/06
Executing arbitrary code by opeing a jpeg file isn't critical?  FatherJ | 04/24/06
Not to a Mac zealot!  NonZealot | 04/24/06
Mac Zealot  fissi | 04/24/06
Can't do that on a PC without a degree  IronCladChicken | 04/25/06
HAHAHAHAHAHAHAHAHA!!!!!!!!  NonZealot | 04/25/06
The arguments here are as ridiculous as the article  mlindl | 04/25/06

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
advertisement
Click Here