toggle

AAPL Stock: 562.29 ( -3.03 )

Exploit may endanger Safari users

updated 10:40 am EST, Fri November 24, 2006

Exploit, Safari users


Security researchers have published an exploit that targets an unpatched kernel vulnerability in Mac OS X which could allow malware developers to take advantage of how Apple's Safari Web browser downloads online image files, and could lead to arbitrary code execution. The new exploit was revealed as part of the "Month of Kernel Bugs," according to eWeek.com, and details the steps necessary for attackers to take advantage of the vulnerability. "Mac OS X fails to properly handle corrupted image structures, leading to an exploitable denial of service condition," wrote the security researcher who discovered the flaw. "Although it hasn't been checked further, memory corruption is present under certain conditions." Security researchers at Secunia rated the exploit as "highly critical," which is the company's second most severe threat ranking, saying that local users could exploit the bug to gain escalated privileges or utilized by malware writers to compromise a vulnerable system. The vulnerability is caused by an error in the Mac OS X AppleDiskImageController, which surfaces when the system handles corrupted image files, according to the report.


by MacNN Staff

toggle

Comments

  1. kjbuckley

    Fresh-Faced Recruit

    Joined: Nov 2006

    0

    *DISK* image files

    Not images (GIFs, JPEGs etc).

  1. jarod

    Fresh-Faced Recruit

    Joined: Apr 2005

    0

    Bloody morons

    If you're gonna post information regarding a security exploit, at the very least post the info ACCURATELY!!.. F***king idiots, I swear to God, some people need to be shot before coming anywhere NEAR a keyboard!

  1. gskibum3

    Fresh-Faced Recruit

    Joined: Nov 2006

    0

    Louzer?

    As full of ignorance this article is one can only conclude Louzer wrote it.

  1. rc5781

    Fresh-Faced Recruit

    Joined: Apr 2007

    0

    Louzer

    ultram drug Discount Ultram No Prescription Needed generic tramadol cheap Discount no prescription tramadol Prozac no prior prescription Buying online prozac Women p*** Free Black p*** brand ultram sample Cheap Ultram Without Prescription cheap soma US Soma sales online Cheap Soma Lowest Cost Cheap Soma On Line Generic fioricet pricing Buying Brand Name Fioricet Purchase Brand Soma generic soma buying information

Login Here

Not a member of the MacNN forums? Register now for free.

 
close
Photo
toggle

Network Headlines

toggle

Most Popular

MacNN Sponsor

Recent Reviews

iHome iW2 AirPlay speaker

iHome generally isn't known as a luxury brand when it comes to audio, but it is prolific -- the company's docks and speakers are every ...

Logitech Ultrathin Keyboard Cover

One of the iPad's main weaknesses has always been productivity. It's not a question of apps; while it has taken a little time for a na ...

Logitech UE Air Speaker

If maybe a little more slowly than Apple would like, AirPlay is becoming a staple of the wireless speaker market for iOS devices. The ...

toggle

Most Commented