Security Flaws Make Macs Vulnerable To Attacks - InformationWeek

InformationWeek is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

IoT
IoT
News

Security Flaws Make Macs Vulnerable To Attacks

Security firm @stake warns of serious Mac OS X vulnerabilities.

Security research firm @stake is warning Macintosh users about three security problems with the Mac OS X 10.2.8 and previous versions. It ranks two of the flaws as high.

The first advisory, "Long argv[] Buffer Overflow," warns that an attacker could possibly crash Mac OS X and execute commands as root.

The Systemic Insecure File Permissions advisory states some applications on the vulnerable Mac OS X systems are installed with insecure file permissions and are globally writable. This lets attackers with file-system access to an OS X machine replace binaries and obtain additional privileges from unsuspecting users, who may run the replaced version of the binary.

The third vulnerability, Arbitrary File Overwrite via Core Files, enables attackers with certain access rights to overwrite arbitrary files and read certain files. The @stake advisory warns that this vulnerability could result in sensitive information such as authentication credentials being compromised.

There is no patch available for these vulnerabilities. The @stake advisory recommends that users upgrade to the Mac OS X Panther operating system, which was released this week.

An Apple Computer spokesperson could not say where the company would issue a fix, but Apple is working on a statement about the issue.

David Goldsmith, director of research for @stake, said there's no indication from Apple that it "was going to release a patch for these issues," and that @stake started working with Apple regarding the security problems "at least 30 days ago."

For more detailed information, the advisories are available at www.atstake.com/research/advisories/2003.

Apple is also warning users about another flaw in the Mac OS X software, a remotely exploitable flaw caused by an error in the implementation of QuickTime Java for Mac OS X Server 10.3 and Mac OS X 10.3. More information about this flaw and a patch is available in Apple's Security Update 2003-10-28.

The flurry of security flaws in Apple's OS X shows "there's no piece of commercial software that doesn't have security problems," says John Pescatore, a security analyst at Gartner. As to whether the company should patch these flaws, he says, "Apple should definitely issue a patch, even if the new operating system is shipping."

We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.
Comment  | 
Print  | 
More Insights
The State of Cloud Computing - Fall 2020
The State of Cloud Computing - Fall 2020
Download this report to compare how cloud usage and spending patterns have changed in 2020, and how respondents think they'll evolve over the next two years.
Commentary
2021 Outlook: Tackling Cloud Transformation Choices
Joao-Pierre S. Ruth, Senior Writer,  1/4/2021
News
Enterprise IT Leaders Face Two Paths to AI
Jessica Davis, Senior Editor, Enterprise Apps,  12/23/2020
Slideshows
10 IT Trends to Watch for in 2021
Cynthia Harvey, Freelance Journalist, InformationWeek,  12/22/2020
Register for InformationWeek Newsletters
Video
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you.
White Papers
Slideshows
Twitter Feed
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Sponsored Video
Flash Poll