Infrastructure
News
2/26/2008
04:34 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Apple's Mac OS X Vulnerable To Networking Exploit

A security researcher at Digit-labs.org posted a proof-of-concept exploit that takes advantage of a flaw in the way the Apple implements IPv6 support.

The most recent version of Apple's Mac OS X (10.5.2) appears contain a security vulnerability that could allow an attacker to crash computers on a local or remote network.

Security researcher Neil Kettle of Digit-labs.org on Tuesday posted a proof-of-concept exploit that takes advantage of a flaw in the way the Apple implements IPv6 support.

Most networks use the IPv4 networking protocol; IPv6 is slowly being deployed to provide a larger number of available network addresses, improved security, and other features.

In an e-mail, Kettle explained that the bug isn't likely to put home users at risk because few of them will be using IPv6 networks.

"In the case of office environments, the bug is more serious since it's more likely IPv6 will be supported on the local network," said Kettle. "One can easily imagine a single user crashing much (if not nearly all) employees' machines at, let's say, Apple Inc."

The bug is also an issue for Mac OS X Server, as more servers provide native IPv6. A single user, Kettle said, could significantly affect server reliability.

The bug resides in the open source KAME Project's IPv6 implementation, which may not properly process IPv6 packets that contain an IP payload compression protocol (IPComp) header. Mac OS X is built atop BSD Unix, which contains KAME Project code.

Kettle observes that the bug was identified in November and that Apple has not acknowledged that Mac OS X is vulnerable. The "very existence of this bug is quite indicative of Apple's patching and security practices," he said.

Comment  | 
Print  | 
More Insights
2014 Next-Gen WAN Survey
2014 Next-Gen WAN Survey
While 68% say demand for WAN bandwidth will increase, just 15% are in the process of bringing new services or more capacity online now. For 26%, cost is the problem. Enter vendors from Aryaka to Cisco to Pertino, all looking to use cloud to transform how IT delivers wide-area connectivity.
Register for InformationWeek Newsletters
White Papers
Current Issue
InformationWeek Tech Digest September 18, 2014
Enterprise social network success starts and ends with integration. Here's how to finally make collaboration click.
Flash Poll
Video
Slideshows
Twitter Feed
InformationWeek Radio
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.