Intego warns of four Apple vulnerabilities
updated 06:20 pm EST, Thu January 11, 2007
Four Apple security flaws
Intego, the makers of programs like VirusBarrier X4, has issued a warning regarding three security vulnerabilities connected to Mac OS X, along with a fourth vulnerability attributed to QuickTime. The QuickTime vulnerability is related specifically to the way Apple's multimedia software deals with RTSP URL handlers. Intego notes that a malicious user could overflow a stack-based buffer, executing chosen code. Further attributed to Apple's work are flaws with folder permissions in Mac OS X 10.4.8, and in the same version, the way file permissions are repaired by diskutil. The final vulnerability is linked with the current Mac port of VLC Media Player, which could affect Mac OS X by exploting VLC's use of UDP addresses. Intego claims that its VirusBarrier X programs can stop attacks on Mac OS X, but will require users to block ports 554 UDP and 7070 TCP to halt the QuickTime bug.






Fresh-Faced Recruit
Joined: Nov 1999
adasdfasd
adfasdfas