Home > Security News > Apple fixes 25 Mac OS X flaws
Security News:
EMAIL THIS

Apple fixes 25 Mac OS X flaws

By SearchSecurity.com Staff
23 Apr 2007 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Apple has released a mega-fix for Mac OS X, sealing about two dozen security holes attackers could exploit to cause a denial of service, bypass security restrictions, disclose sensitive data and run malicious code on targeted machines.

The 25 flaws include the following:

  • An error in the AFP Client that executes commands without properly cleaning the environment. Local attackers could exploit this to create malicious files or execute arbitrary commands with system privileges.

  • A buffer overflow error in the AirPortDriver module that surfaces when malformed control commands are processed. Attackers could exploit this to run malicious code with elevated privileges on eMac, iBook, iMac, PowerBook G3, PowerBook G4, or Power Mac G4 systems equipped with an original AirPort card.

  • An error in the CoreServices interprocess communication local users could exploit to obtain a send right to the Mach task port and execute arbitrary code with elevated privileges.

  • An error in Libinfo that does not properly report errors to applications. Malicious Web sites could exploit this to run malicious code.

  • An integer overflow error in the RPC library that surfaces when the operating system processes malformed requests sent to the portmap service. Attackers could exploit this to cause a denial of service or run malicious code with "daemon" privileges.

  • An error in the software update window that may appear beneath the login window when a scheduled task is run under certain conditions. Attackers could exploit this to log in without authentication if they have physical access to the system.

  • A design error where the username and password used to mount remote filesystems through connections to SMB servers are passed to the "mount_smb" command as command line arguments, which could be exploited by a local attacker to obtain other user's authentication credentials.

    Tags: Alternative OS security: Mac, Linux, Unix, etc.VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Alternative OS security: Mac, Linux, Unix, etc.
    Machiavelli Mac OS X rootkit unveiled at Black Hat
    How secure is 'Platform as a Service (PaaS)?'
    Security comparison: Mac OS X vs. Windows
    Mac OS memory flaws pose challenges for enterprise endpoint protection
    Rootkit Hunter demo: Detect and remove Linux rootkits
    Oracle to buy Sun Microsystems for $7.4 billion
    How to harden Linux operating systems
    Serious holes in Mac OS X memory, researcher shows
    What is the best operating system for an FTP server implementation?
    Black Hat DC 2009: Mac OS attack method
    Alternative OS security: Mac, Linux, Unix, etc. Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    trusted computing  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • More Tips to Secure Your Network
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts