Security flaws surface in Leopard, VPN
updated 05:25 pm EST, Mon December 10, 2007
Security flaws in Leopard
A new denial of service (DoS) vulnerability has surfaced in Apple's Mac OS X Leopard operating system that can result in crashes, according to Heise Security. The flaw, which is an integer overflow in the load_threadstack function in mach_loader.c, occurs when processing Mach-O binaries and can lead to a kernel panic. Single user systems should not be at risk, according to the company, but multi-user setups are vulnerable because attackers do not require any special privileges to provoke the error.
Additionally, security website digit-labs.org has reported a DoS vulnerability in the VPN (Virtual Private Network) service in Mac OS X 10.5 where maliciously-crafted packets can cause the service to freeze. Demonstration exploits are available for both flaws, and no patches have been released to correct the problems.






Fresh-Faced Recruit
Joined: Nov 2005
hei(bs)e
Heise must have a team of people doing nothing but trying to find ways to crash OSX.
None of this c*** they publish is in the wild - they are all (wow, what a surprise) only in their own lab. Now, if they were actually an ethical company they would notify Apple of the problem and allow them to issue a notice or make corrections - instead of using their self-made flaws as a way to extend their own business.
Doofuses.