|
MoAB completes hat trick of DMG bugs |
|
|
by Stephen Withers
|
|
Friday, 12 January 2007 |
Targeting Mac OS X's handling of disk image (DMG) files for the third successive day, the Month of Apple Bugs has demonstrated a way of exploiting an integer overflow in a routine within the filesystem code.
Unlike yesterday's bug, this one is said to be Mac OS X specific. The good news is that "Abuse of this issue for arbitrary code execution seems unlikely", according to discoverer LMH.
The MoAB Fixes group is considering the development of a utility to check DMG files for the various conditions identified by MoAB. One possibility is that it could be set as the default application for opening DMG files, forwarding them to DiskImageMounter as usual if they pass inspection.{moscomment}
|