DealsOnTheWeb Daily Deal: OneCall's Weekend Sale - 20 Great Items at Great Prices All Weekend Long
Mac OS X Security Risk Published
by , 9:10 AM EDT, June 30th, 2006
Proof of concept information about a potential security flaw in Mac OS X has been released, elevating the need for Tiger users to install the Mac OS X 10.4.7 update. According to ZDNet, the flaw, which takes advantage of a vulnerability in the launchd system component, was one of the fixes included with Apple's latest system update that was released earlier this week.
An Apple spokesperson commented "This proof of concept was fixed in Tuesday's Mac OS X 10.4.7 update."
The launchd proof of concept was created by Kevin Finisterre, a security researcher at Digital Munition, and requires local access to a Mac instead of Internet access. The security flaw could allow someone to execute code on your Mac with higher privileges that the logged in account allows.
So far, there are no known reports of anyone using the launchd proof of concept information to develop an exploit for Mac OS X.
Observer Comments
Quotehangtown wrote:
AND requires local access to the machine.
Still not overly significant, even if it were more than a concept.
I could see it being a problem in a school situation with their student accessible networks. I am glad that Apple got the fix out before the published vulnerability.
Just a reminder to everyone that most vulnerabilities are not published until a fix has been released. It's in consideration for the company that has the vulnerability. They go through a process of first notifying the company of the vulnerability. The company then fixes said vulnerability and then the company/person that found the vulnerability usually has first rights to publish the vulnerability at that time which is a thank you nod from the vulnerable company for notifying them first and not all the hackers out there.
Problems, big problems arise when company/people notify the public first about the vulnerability, or only wait a little time after notifying the vulnerable company to notify the public. This puts a lot more people at risk then if they would have kept quiet until the company fixed the problem and released a patch.
Ok that was confusing, but hopefully it's clear enough to make the point. ![]()
Recent Headlines - Updated Friday, July 4th, 2008
- Fri., 7:30 AM
- Happy Fourth of July!
- Thu., 4:50 PM
- Apple Slashes $400 from SSD Drive in MacBook Air
- 4:05 PM
- It's Official - Firefox Sets Guinness Record for Downloads
- 3:30 PM
- Apple Files Patent for a Multi-touch Gesture Language
- 2:20 PM
- Editorial - Mac's Market Share and the Cascade Failure of Windows
- 1:35 PM
- iPodObserver - Apple Slurps Up Samsung's NAND Flash for iPhone 3G
- 1:05 PM
- WSJ: Tips for Switching from Windows to Mac
- 12:05 PM
- iPodObserver - Google Intros Google Talk for iPhone
- 11:35 AM
- iPO Just a Thought - iPod nano Versus iPhone: Decisons, Decisions...
- 10:55 AM
- YouTube Ordered to Turn Over All User Records to Viacom
- 10:10 AM
- Hot Forum Topic - Apple vs. Cell Carriers: Who's Winning the Game
- 9:25 AM
- iPodObserver - Rumor: Best Buy, Radio Shack to Sell iPhone 3G
- 8:45 AM
- .Mac Bookmark Sync Deadline Extended to July 6
- 8:10 AM
- Adobe Reader 9 Hits the Streets
The Mac Observer Reader Specials
- Download Typestyler, still the Ultimate Styling Tool for Internet, Print and Video Graphics. Works great in Classic with a Native OS X Version on the way. Free Tryout: www.typestyler.com
- OWC: Upgrade to a Larger Hard Drive, Add Additional Drives SATA for Mac Pro and G5s, up to 1.0TB in each Bay. 500GB from $90!
New MacPro Memory 800Mhz With Apple Spec Heat Sink 2GB $104 / 4GB $172 / 8GB $338. Click to Maximize your Macs...
Mac observers can now play Party Poker for Mac as well as Mac casino games by going to MacPokerOnline.com.
RamJet Memory: MacBook 1Gig $39, 2Gig $78, 4Gig $195! Mac Pro 2Gig $115, 4Gig $189! 500G Seagate SATA II $139! Click hereFor the latest Apple products use Ciao a comparison website to find laptops like MacBook Air. Then find the best prices on MP3 players and use our comparison tool to evaluate cell phones.
Laptop Hardware Provided by TechRestore - Overnight Mac & iPod Repairs.


