View this article at: http://www.macnn.com/articles/05/01/18/darwin.audit.finds.flaws/
Tuesday, Jan 18, 2005 9:45pm
Darwin audit finds flaws th...
A source-code audit of the open-source Darwin revealed four vulnerabilities of varying severity, according to ImmunitySec, the security firm who conducted the audit. CNET News.com reports that the flaws affect Mac OS X 10.3 Panther, which is built around Darwin. A security advisory released by the ImmunitySec says the bugs mostly affect remote systems with multiple users and that since Mac OS X is most often used on the desktop, the flaws will not be overly important on most people's systems. The company originally found the flaws in June, but only published them to a private list of customers and not notify Apple. On Monday it publicized the flaws, which include "a bug in Mac OS X's SearchFS function, several kernel memory overflows and a logic bug in the AT command, which is used to schedule tasks by the operating system."