Newsletter:

Skip Navigation LinksHome > News > Security > New exploit published for Mac OS X

New exploit published for Mac OS X

By Shaun Nichols
23 November 2006 09:54AM
Tags: exploit | published | mac | os

Month of Kernel Bugs highlights yet another Apple vulnerability.

A security researcher has posted proof-of-concept code for a 'highly critical' vulnerability in Apple's OS X operating system. 

The exploit targets a component used to run Apple's .dmg disk images files. The .dmg format is commonly used to compress programs for download and is similar to the .iso format used in Windows.

A security researcher using the initials 'LMH' posted details about the vulnerability as part of the Month of Kernel Bugs project. 

The author claimed that the exploit could easily be executed in Apple's Safari web browser through a specially crafted .dmg file launched when a user visits a webpage.

According to LMH, the threat can be mitigated in Safari by disabling a setting in the browser's preference panel that reads 'Open 'safe' files after downloading.'

Disabling the setting will prevent .dmg files, images, movies and PDF files from automatically opening after they have been downloaded.

Security firm Secunia rates the vulnerability as 'highly critical', its second-highest threat level. It is the highest alert level given to a Mac OS X vulnerability since the publication of an official Apple security update in early October. 

The Month of Kernel Bugs project has vowed to post new proof-of-concept or exploit code every day for the entire month of November.

Apple did not respond to a request for comment.

Copyright © 2008 vnunet.com

   


Ads by Google





Product Reviews

Star Rating
The Kerio WinRoute Firewall is an interesting product for this category.
Star Rating
The BiGuard S6000 extends the network to the remote user with features such as Network Extender, Transport...
Star Rating
Sendmail Sentrion DS 3.0 is a rack-mounted email authentication appliance used strictly for applying digital...
Like the sky box in a sports stadium, Skybox SRM offers an overall view of everything.
Star Rating
The offering from Symantec is much larger than the scope of this review.
ITNews NetSeminars
TopTopics
(20603) -  iphone
(6733) -  internet
(4686) -  accc
(3599) -  hack
(3512) -  apple
(3505) -  microsoft
(3266) -  telstra
(3226) -  government
(3027) -  vista
(2708) -  smartphone
(1992) -  security
(1855) -  web
(1712) -  yahoo
(1696) -  online
(1627) -  spam