Security researcher Neil Kettle of Digit-labs.org on Tuesday posted a proof-of-concept exploit that takes advantage of a flaw in the way the Apple implements IPv6 support.
In an e-mail, Kettle explained that the bug isn't likely to put home users at risk because few of them will be using IPv6 networks.
"In the case of office environments, the bug is more serious since it's more likely IPv6 will be supported on the local network," said Kettle. "One can easily imagine a single user crashing much (if not nearly all) employees' machines at, let's say, Apple Inc."
The bug is also an issue for Mac OS X Server, as more servers provide native IPv6. A single user, Kettle said, could significantly affect server reliability.
The bug resides in the open source KAME Project's IPv6 implementation, which may not properly process IPv6 packets that contain an IP payload compression protocol (IPComp) header. Mac OS X is built atop BSD Unix, which contains KAME Project code.
Kettle observes that the bug was identified in November and that Apple has not acknowledged that Mac OS X is vulnerable. The "very existence of this bug is quite indicative of Apple's patching and security practices," he said.
Stay connected and informed by visiting our Enterprise IT Community!

Become a member today for instant access to free InformationWeek research, expert advice, peer perspectives, and more on the following topics:
- Application Performance Management (APM)
- Security Management
- Mainframe 2.0
- IT Automation
- Service Assurance
Also, visit our Government, Retail and Financial Services groups to see how these technologies apply specifically to those industries.
NOTE: Offer valid for U.S., U.S. possessions, & Canada only.