Home » Featured, Mac OS X, News

Flaw in Mac OS X 10.5 and 10.6 can be exploited by a remote attacker

By Mac Hack PC 12 January 2010 View Comments

Apple is aware of this security flaw since last June which was first reported by researcher Maksymilian Arciemowicz. Few days ago Security Researcher at SecurityReasons posted a detailed report on this flaw. The effected software is for Mac OS X 10.5 and 10.6 with a security risk HIGH. Which means – It is used for Buffer overflow vulnerabilities and Remote file inclusion (RFI) vulnerabilities. Also it is used for vulnerabilities that can lead to system compromise and remote command execution. Usually vulnerabilities are remotely exploitable and does not require any user interaction. In other words, it will be very easy for attacker to remotely access your system.

SecurityReasons Mac OS X Flaw

The bug in questions affets the libc/strtoc(3) and libc/gdtoa functions in Mac OS X, as well as other Unix based operating system. FreeBSD amd NetBSD have fixed the flaw, but Apple for some reason kept this a side. Because these functions are used in many applications, this could be a vector of attack by remote users via web browsers, e-mail clients and more.

In the report they have also informed that Local and Remote Exploits are possible. That means -  attacker is authenticated user and require access to the system and also the attacker can remotely take over vulnerable application and don’t need access to system or local network.

For all Mac OS X users, please keep your eyes open for any malware that attempts to exploit any vulnerability. I hope, Apple will take this matter very seriously and inject a fix  as soon as possible.

Source[via]

If you would like to comment on this post please do..

To know more.. , you can always follow us on twitter @machackpc (News, Tips, Tweaks, Hints, Hacks and Updates on your PC, Mac, Linux, iPhone, Other Phones and any other technology related)

Articles you may be interested in

If you enjoyed this post, make sure you subscribe to my RSS feed!

Related Posts with Thumbnails

  • How to get your ECID Number for Mac Users
  • Make your winter glove work on iPhone
  • Watch Steve Jobs Keynotes in just under 5 minutes [Video]
  • How to Jailbreak iPhone 3G running iOS 4 using redsn0w (Windows)
  • How to painlessly root your Droid Incredible running Android OS 2.1 (unrevoked)
  • Apple released 3rd Build Mac OS X 10.6.4 (10F50) to selected developers.
  • Apple's iPad software update is imminent (Confirmed)
  • Web Plugin by Christopher Ross


    blog comments powered by Disqus