The code, which has appeared on the "milw0rm" site, exploits a bug that Apple Computer identified within the operating system's kernel. According to the security update advisory Apple released Friday, the flaw is in a kernel error-handing mechanism known as "Mach exception ports" that controls programs when certain types of errors are generated.
A successful exploit, Apple said then, could let an attacker introduce his own code to an unpatched Mac running OS 10.4.1 though 10.4.7.
"The exploit payload executes /usr/bin/id, and as such would need to be replaced with a more useful payload to be used effectively," noted Symantec in an alert to customers of its DeepSight threat system.
IT's Reputation: What the Data SaysInformationWeek's IT Perception Survey seeks to quantify how IT thinks it's doing versus how the business really views IT's performance in delivering services - and, more important, powering innovation. Our results suggest IT leaders should worry less about whether they're getting enough resources and more about the relationships they have with business unit peers.
What The Business Really Thinks Of IT: 3 Hard TruthsThey say perception is reality. If so, many in-house IT departments have reason to worry. InformationWeek's IT Perception Survey seeks to quantify how IT thinks it's doing versus how the business views IT's performance in delivering services - and, more important, powering innovation. The news isn't great.