On GameSpot: Wii Fit tells 10-year-old she's fat
BNET Business Network:
BNET
TechRepublic
ZDNet

By Elinor Mills
Posted on ZDNet News: Nov 21, 2006 10:17:00 PM

A security researcher has published attack code for an unpatched flaw in Mac OS X, the latest vulnerability in the "Month of Kernel Bugs" campaign.

The proof-of-concept code exploits a security hole in the way Apple Computer's operating system handles disk image files, the researcher wrote Monday on a blog devoted to the campaign, which promises to reveal details of a new flaw in low-level software every day this month.

"Mac OS X com.apple.AppleDiskImageController fails to properly handle corrupted DMG (disk image) image structures, leading to an exploitable memory corruption condition with potential kernel-mode arbitrary code execution by unprivileged users," wrote the researcher, who goes by the initials "LMH."

The vulnerability could be exploited remotely, as Apple's Safari Web browser loads DMG files from external sources, such as one found while visiting an URL, LMH wrote. That could let an outsider compromise a system.

Secunia rated the vulnerability as "highly critical" in an advisory on its Web site on Tuesday. In addition to being used to compromise a computer, the flaw could be exploited by malicious local users to gain escalated privileges to the system, the security company said.

Apple representatives did not respond to a request for comment.

In the blog, researcher LMH said people can prevent an attack by "changing the Preferences and deactivating the functionality for opening 'safe' files after downloading."

Vulnerabilities in the Mac OS have been rising, leading some experts to note that the Macintosh platform is not impervious to security problems. The vast majority of security vulnerabilities affect computers running Microsoft Windows.

  • Talkback
  • Most Recent of 78 Talkback(s)
Macs ARE vulnerable
It is about time that the hogwash of Apple's zero vulnerability in their OSs, and those who keep passing this hogwash around, be exposed for what is really is. Lies, lies, lies.

No computer pr... (Read the rest)
Posted by: lamp299 Posted on: 11/28/06 You are currently: Logged In as: a Guest  | Login | Terms of Use
Nothing to be afraid of  NonZealot | 11/21/06
Weren't you asking about Schadenfreude the other day?  tic swayback | 11/21/06
Hmm, care to point it out?  NonZealot | 11/21/06
Look in the mirror  tic swayback | 11/21/06
Done  NonZealot | 11/21/06
Be careful! They will drag out the strawman again!  Cayble | 11/22/06
OK...what is the difference between an "appologist"  Laff | 11/22/06
How many is too many?  tic swayback | 11/22/06
typical tic. As usual  Cayble | 11/23/06
Well, I'm sure we'll all get  999ad@... | 11/21/06
Same defense holds  NonZealot | 11/21/06
We Seek Your Approval to Switch  Harry Bardal | 11/21/06
To equate Ballmer saying that he ...  ShadeTree | 11/21/06
Hmmmmm  thepubba | 11/21/06
NonZealot died for your sins  tic swayback | 11/22/06
Okay it was a stretch!  ShadeTree | 11/22/06
Defenders of the Realm!  nomorems | 11/22/06
As a MAC user...  Information_z | 11/22/06
Info_z... Actually MS has...  MacCanuck | 11/24/06
A critical flaw?  georgep_z | 11/22/06
When you have your own ....  ShadeTree | 11/22/06
That logic does not sound right too me......  Laff | 11/22/06
Yes that is right.  ShadeTree | 11/22/06
No,  fuzzy2k | 11/22/06
howmany2many  hirez | 11/22/06
As more and more  Mectron | 11/21/06
So even you agree that more and more will be using OSX?  Laff | 11/22/06
Well....  Badgered | 11/22/06
Attack code targets zero-day Mac OS X flaw  Loverock Davidson | 11/21/06
It wouldn't work on my machine  j.m.galvin | 11/21/06
Flaw is for *current* Intel based Macs  john.murray@... | 11/22/06
Because the headline reads  j.m.galvin | 11/22/06
Interesting..  thatxbxtchxnicoll | 11/22/06
Agree!  bgonetoo | 11/21/06
what [yawn] was [yawn] that [yawn] about . . .  brian ansorge | 11/21/06
You got the quote wrong again  NonZealot | 11/21/06
Be careful NZ...  tic swayback | 11/22/06
Incorrect response  tic swayback | 11/22/06
Ah but the difference is  Loverock Davidson | 11/22/06
Really?  tic swayback | 11/22/06
Well, yes.... yes it should.  Badgered | 11/22/06
Given the sheer numbers...  tic swayback | 11/22/06
See, now you're going a bit off track  Badgered | 11/22/06
So now you are saying that marketshare DOES count?  Confused by religion | 11/22/06
I'll count on you in the future then...  tic swayback | 11/22/06
Marketshare has always counted  tic swayback | 11/22/06
RE: I'll count on you then  Badgered | 11/22/06
There is no corelation between ...  ShadeTree | 11/22/06
More data is needed....  tic swayback | 11/22/06
tic, let's use your data  NonZealot | 11/22/06
Perhaps you're on to something...  tic swayback | 11/22/06
right?  Badgered | 11/22/06
Oopsy!  tic swayback | 11/22/06
"the most secure version of windows, ever..."  nix_hed | 11/23/06
another proof of concept, without full proof  doh123 | 11/22/06
This was fixed nearly a year ago.  crash89 | 11/22/06
Wasn't that during the whole Widget foofaraw?  tic swayback | 11/22/06
It's off  thatxbxtchxnicoll | 11/22/06
Re: This was fixed nearly a year ago.  jtshaw | 11/22/06
When will they run the Mac attack contests  Boot_Agnostic | 11/22/06
I told you so!  Resuna | 11/22/06
The *flaw* is something you have to turn on.  thatxbxtchxnicoll | 11/22/06
It's on by default.  Resuna | 11/22/06
the last sentence  einsteintech | 11/22/06
Here's a link to the actual website on which the source is  BillyB40 | 11/22/06
Mac Attack  rbert16000 | 11/22/06
With stunning logic like that  NonZealot | 11/22/06
A linux penguin attack  Boot_Agnostic | 11/23/06
And you've tried them all...  John Zern | 11/24/06
Ballmer  rbert16000 | 11/22/06
wow- another proof of concept!  hirez | 11/22/06
real world  TWRX | 11/22/06
2007- The year of the Mac attacks?  ghastly | 11/27/06
Choosing to disagree...  ladyirol | 11/28/06
Notoriety?  NonZealot | 11/28/06
All of this to get 1-5% of users  moffett.john@... | 11/28/06
Small Fan Base  moffett.john@... | 11/28/06
Macs ARE vulnerable  lamp299 | 11/28/06

What do you think?

advertisement
Click Here