Telstra has revealed the addition of almost one million new mobile services in the six months to December 2011, but Sensis revenues plummeted 24 percent in 12 months.
Today's instalment in the Month of Apple Bugs is a format string vulnerability in Software Update, the utility used to download and install patches and new versions of Apple software.
We can't help wondering if the MoAB team has deliberately chosen to end the month with a series of flaws in software shipped by Apple rather than third party developers.
Format string vulnerabilities have identified in previous disclosures, and involve passing a string containing formatting commands such as %x in circumstances when the program concerned doesn't expect them.
In this case, the exploit involves opening a .swutmp file with an appropriately crafted name, causing a crash and potentially allowing the execution of arbitrary code. Files with this extension are opened by Software Update, but the trick would be in persuading the recipient to open the file or arranging matters so that it is opened without user intervention. The MoAB team says they "are conducting further tests around Software Update and possible vectors to abuse this issue."
No workaround is offered: "Wait for Apple to release a patch for Software Update via Software Update" is the tongue-in-cheek advice.
Temporary patches for previous format string vulnerabilities have offered by the MoAB Fixes group.
David Bass
| For the fourth year in a row, IDC has placed content security provider Websense (NASDAQ: WBSN) at the top of the IDC Worldwide Web Security 2011 –…
How to Make Business Discovery Work for Your Business
Business Discovery takes its cues from consumer apps. Like Google, it encourages us- ers to hunt for and explore data without worrying about or even noticing the underly- ing technology. Their entire experience is working within an intuitive interface to get real-time, self-service results with only minimal training. ...more
Try an easy-to-use set of web-enabled
tools for business-class productivity services. Office 365 provides
anywhere-access to email, important documents, contacts, and calendars
on almost any device.