Follow iTWire on Twitter

About iTWire

iTWire is all about technology news, information, jobs and community for the IT and telecommunications industry professional. Subscribe to our free ICT daily newsletter
Apple bug hunters turn attention to AppleTalk E-mail
by Stephen Withers   
Monday, 15 January 2007
The Month of Apple Bugs broke fresh ground today, highlighting a buffer overflow in Mac OS X's AppleTalk stack.

According to LMH, insufficient checking by a particular function "leads to a denial of service condition and potential arbitrary code execution by unprivileged users. Remote exploitation might be possible".

The proof of concept just causes a kernel panic.

Yesterday's bug was another DMG (disk image file) exploit, this time using a malformed HFS+ filesystem. Like the previous exploit, it carries a risk that other mounted filesystems may be corrupted. The outcome of that is more likely to be serious than with the UFS exploit, as most Mac hard drives use HFS+.

Landon Fuller of the MoAB Fixes group is disinclined to offer kernel patches (the filesystem and AppleTalk issues are kernel related), writing "The stakes are much higher when patching the kernel... I don't want to provide a cure that's worse than the disease."

The group is continuing work on a utility to 'sanity check' DMGs prior to mounting them.{moscomment}
Powered By Joomla Tags

Please enable JavaScript in your browser to post your comment!

 
< Next story in category   Previous story in the category >
iTWire user statistics Visitors last 30 days
694,279
Subscribers 15,210
#1 independent technology news advertise here
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff

- Advertisement -

Featured Whitepapers

1