RSS RSS Twitter Twitter
troubleshooting/tutorials/security

11/17/2003, 11:35am, EST

Monday, November 17th

Serious Mac OS X file-save bug could delete files

MacNN readers note a serious file-save bug that affects all Cocoa application, which could caused deletion of an entire (non-boot) partition: "If you try to save a file with a name that is *much* too long (say, 1000 characters), OSX will apparently suffer some kind of buffer overflow, and overwrite the folder you're trying to save that file into. It will warn you that it might overwrite something, but if you're not paying attention or if you instinctively hi enter... You could potentially completely overwrite a partition (obviously not the system drive for permission reasons, but any partition), if you're saving at the root of that partition."


Filed under: troubleshooting

, , 57comments, del.icio.us, slashdot, digg, buzz , Twitter



57 comments
Reader Reactions (Please use <i></i> for italic text)

subscribe to comments
for this article




Expand All   Global Settings
Yeah but...
0
11/17, 11:43am, EST
who ever names a document with more than 1000 charecters?
Fresh-Faced Recruit
Joined Jul 2001
User is offline
genome research
0
11/17, 11:45am, EST
1000 character long filenames are really useful. Considering having to save a file according to the name of a specific part of the genome. You know, those scientists switched from DOS and it's 8.3 character limitations precisely because of this reason alone, the ability of the Mac to use longer filenames than DOS. and OS X leads in that tradition.

The longer the filename, the more of the genome we can save. Hopefully with the release of Mac OS Puma, scientists will be able to utilize 2,000 character names, perhaps allowing for mutation research within the human genome, finally!!
Fresh-Faced Recruit
Joined Jul 2001
User is offline
for the rest of us...
0
11/17, 11:47am, EST
for the rest of us who aren't studying the human genome... whoopydifreak'ndo! who cares.
Fresh-Faced Recruit
Joined Jul 2001
User is offline
This is a real problem...
0
11/17, 11:52am, EST
I like to be very descriptive when I name my files. 1000 characters is nothin'. What was Apple thinking? How could they release an OS with such a hidious limitation? Windoze here I come...

Come on, get real! I've been using and fixing Macs for about 20 years and to say that this is a problem is crazy. It would be simpler for a hacker to just format the drive or partion than to try and save a file with a name 1000 characters long. Geez!
Fresh-Faced Recruit
Joined Jul 2001
User is offline
This "problem" is as...
0
11/17, 11:57am, EST
....likely to hurt me as I am to see a flock of pigs zoom by my window.
Fresh-Faced Recruit
Joined Jul 2001
User is offline
Re: This "problem"
0
11/17, 12:04pm, EST
No kidding... people whine and bitch about the apparent lack of attention to security in OS X, and then they come up with crap like this for an example.

Ridiculous. You couldn't hack an OS X box if you tried, and even if you could, you'd have to use some obscure method like activating the screensaver and typing the commands at light speed before the password dialogue pops up or trying to save a file with more than 1,000 characters in the name. Windows, on the other hand, can be exploited and compromised by an 11 year old using an old 75MHz Pentium and a dial-up connection.
Fresh-Faced Recruit
Joined Jul 2001
User is offline
Get Serious!
0
11/17, 12:10pm, EST
How can this bug be considered to be a SERIOUS ??

It is a data loss bug and should be fixed, but it is not a serious problem for ANYONE.

Fresh-Faced Recruit
Joined Jul 2001
User is offline
It is a bug
0
11/17, 12:12pm, EST
If it is a bug, it could cause a problem, and therefore it should be fixed. I'm not sure why people defend Macs no matter what is the problem. I'm convinced if someone found a bug that would cause their Mac to explode, people would post in this forum and claim it was somehow a positive feature by Apple.
Fresh-Faced Recruit
Joined Jul 2001
User is offline
Puma?!
0
11/17, 12:14pm, EST
Puma has already come and gone... that was the codename for the original Mac OS X 10.0.0

It's a buffer overflow problem -- the same thing that affected the screensaver password until it was fixed.
Fresh-Faced Recruit
Joined Jul 2001
User is offline
Hmmmmmm
0
11/17, 12:15pm, EST
Can you still use .doc or a three letter extension after the 1000 character file name? I wouldn't want to forget what kind of file I'm saving.
Fresh-Faced Recruit
Joined Jul 2001
User is offline
additional comments:..1..2..3..4..5..6..Next
Your Comments

In order to post comments: If you are a registered member, please login with your MacNN Forums username and password otherwise please uncheck the checkbox below.


Registered Member?
macnn forums login:

macnn forums password:

Not a member of the MacNN forums? Register now for free.

RSS Feeds

Have the latest content delivered to your desktop via RSS. Use the links below to get access to a specific blog, news, or reviews feed.



  MacNN -all

  MacNN Reviews

  MacNN Podcasts

  iPodNN

  Electronista

  Left Lane News
Want To Sell Your Laptop? Any Condition - receive Top Cash. Get an instant quote. Free shipping www.CashForLaptops.com

Internet Marketing School - 100% Online: Master SEO, SEM, E Commerce, Media & More with a U of San Francisco Certificate.

Buy from The Apple Store, iTunes.com, Amazon.com, TechDepot, OfficeDepot, Computers4Sure, or donate.