Secunia Reports Mac OS X FTP Vulnerability

· by · News

The security firm Secunia is reporting that it has uncovered a buffer overflow vulnerability in Mac OS Xis ftpd function. The report states that if a system is compromised with this exploit, an attacker could potentially execute arbitrary code on the machine or launch a denial of service attack.

The vulnerability affects Mac OS X 10.3.9 and 10.4.8, but other version of the operating system may be vulnerable, too.

The FTP sharing service built into Mac OS X is disabled by default. If you arenit sure if it is running on your Mac, hereis how to check:

  • Go to Apple menu > System Preferences to launch System Preferences.
  • Select the Sharing Preference Pane.

  • Disable FTP Access.
  • Click the Services tab.
  • Make sure that FTP Access is unchecked.

This potential exploit assumes that your Mac is visible to other computers on your network, or on the Internet. If you use a properly configured firewall to block your visibility on the Internet, itis unlikely that anyone outside of your local network will be able to find your Mac to attempt an attack.

There are no known reports of this exploit being used.

Jeff Gamet

Jeff Gamet

Jeff is the Mac Observer's Managing Editor, and co-host of the Apple Context Machine podcast. He is the author of "The Designer's Guide to Mac OS X" from Peachpit Press, and writes for several design-related publications. Jeff has presented at events such as Macworld Expo, the RSA Conference, and the Mac Computer Expo. In all his spare time, he also co-hosts the We Have Communicators podcast, and makes guest appearances on several other podcasts, too. Jeff dreams in HD.

Sign Up for the Newsletter

Enter a valid email address

Join the TMO Express Daily Newsletter to get the latest Mac headlines in your e-mail every weekday.

Adding to list…

No Comments

Add your comment

Commenting is not available in this channel entry.