| Apple bug hunters turn attention to AppleTalk |
|
| by Stephen Withers | |
| Monday, 15 January 2007 | |
The Month of Apple Bugs broke fresh ground today, highlighting a buffer overflow in Mac OS X's AppleTalk stack.Featured Whitepaper
5 Best Practices for Smartphone Support
The proof of concept just causes a kernel panic. Yesterday's bug was another DMG (disk image file) exploit, this time using a malformed HFS+ filesystem. Like the previous exploit, it carries a risk that other mounted filesystems may be corrupted. The outcome of that is more likely to be serious than with the UFS exploit, as most Mac hard drives use HFS+. Landon Fuller of the MoAB Fixes group is disinclined to offer kernel patches (the filesystem and AppleTalk issues are kernel related), writing "The stakes are much higher when patching the kernel... I don't want to provide a cure that's worse than the disease." The group is continuing work on a utility to 'sanity check' DMGs prior to mounting them.{moscomment} |
| < Next story in category | Previous story in the category > |
|---|






Tags




