The Mac Observer

Skip navigational links

DealsOnTheWeb Daily Deal: 16GB iPod Touch: $299 Delivered - $30 Drop

FrSIRT Reports Mac Denial of Service Flaw

by , 8:20 AM EST, November 27th, 2006

The computer security watchdog group FrSIRT is reporting a new potential security threat to Mac OS X that could result in a denial of service attack. The threat takes advantage of a flaw in the kevent() function when registering certain kernel events and allows local unprivileged users to cause the system to panic.

The attack requires direct access to the affected computer, so the threat of theft or physical vandalism is probably greater than the potential for a denial of service attack.

This security threat impacts Mac OS X10.4.8 and earlier, and Apple has not yet released a security update to fix the issue. It is considered low risk, and there are currently no known instances of the exploit being used.

Digg!

Observer Comments

Show: Subjects Only | Full Comments
View Name:Guest
Subject: Danger. Security flaw allows denial of service
Close Name:horvatic Posts: 99 Joined: 27 Jun 2003
Subject: This threat is beyond low it's more like buried

I would hardly call this a threat when you need direct access to the system. This so called threat is beyond low it more like buried.

View Name:Guest
Subject: Wait a second...
Close Name:Mikuro Posts: 450 Joined: 15 Jun 2002
Subject: Who said it was a big deal?

At least these people are actually being honest about this risk. They're not blowing it out of proportion like fear-mongers, the way most of these reports do.

A security hole doesn't need to be exploitable over the Internet to matter. For most home users, something that requires physical access isn't too scary, but in offices, schools, libraries, etc., it matters just as much as, if not more than, remote attacks.

Although as far as any kind of attack goes, causing a simple crash IS pretty ho-hum. You might as well just turn off the machine. *shrug* Definitely low-risk. When something like this makes it to a news site, you know the state of Mac security is pretty damned good.

Comment on this Article


You cannot edit your comments.   You cannot delete your comments.
Log in | Register | Having Problems? Reset TMO Cookies & Try Again
Username:   Password:   Log me on automatically each visit   

You are not logged in, and this post will appear as "Guest." Log in with your username and password from the TMO forums. If you do not have a username, you can register here.
Please note that guests are limited to including a maximum of two URLs per post.


Post A Comment
  Subject


  Your Comments



Please enter the word exactly as you see it in the image above. Registered users aren't prompted for this. Having trouble reading the image get a new one.


Recent Headlines - Updated Friday, July 25th, 2008

Fri., 3:05 PM
iPodObserver - Barron's: iPhone 3G Push E-mail with Exchange a Delight
2:20 PM
iPodObserver - Gartenberg: Zune Phone Unlikely
1:35 PM
iPodObserver - TopMuffin Tracks iPhone Avialability All Day
1:05 PM
CheckUp 1.2 Adds Wi-Fi Network Detector
12:40 PM
AOL Cuts Back on Blogs to Save Cash
11:35 AM
Mac Gaming News - Macgamestore Intros SCRABBLE Journey for the Mac
10:25 AM
Hot Forum Topic - Hunting for iPhones
10:00 AM
iPO Review - Griffin Elan Form
8:35 AM
AirPort Extreme 2008-002 Fixes Tiger Audio Issues
7:30 AM
TMO Quick Tip - Address Book: Selectively Hiding Your vCard Info
 

The Mac Observer Reader Specials

  • Special Report: WWDC 2008
  • Special Report: iPhone
  • __________
  • Help TMO Grow
  • Podcast: Mac Geek Gab
  • Podcast: Apple Weekly Report
  • TMO on Twitter!
  • New Media Expo 2008

Apple Stock Quote

  • AAPL: $162.27. Change Today: +3.24.
  • (Prices delayed up to 20 minutes.)
  • Discuss in our Apple Finance Board

Hot Topics

Top Deals From DealsOnTheWeb