Free Newsletter GlossaryContact UsAbout Us
Coding & ScriptingDesign & ProcessToolsBusiness & Careers

April 21, 2006

Mac OS X Hit By 6 New Zero-Day Bugs



Courtesy of TechWeb News

At least six zero-day vulnerabilities in Apple Computer Inc.'s Mac OS X were disclosed earlier this week by an independent researcher, who noted that all can crash applications or the operating system, and some may let attackers hijack systems.

Four of the bugs relate to how the Mac's OS parses various image file formats -- including BMP, TIFF, and GIF, one to how OS X decompresses malformed ZIP archives, and "several" affect Apple's Safari browser, said researcher Tom Ferris in numerous advisories posted Wednesday to his Security Protocols site.

All impact OS X 10.4.6 -- the most-current edition -- as well as earlier editions, said Ferris, who added that they can result in localized denial-of-service (DoS), in other words "crashes," and may be further exploitable by attackers installing their own malicious code on compromised Macs.

Danish vulnerability tracker Secunia collectively ranked the flaws as "Highly critical" on Friday. For his part, Ferris rated the Safari vulnerabilities as posing the greatest threat, and in his advisory included links to basic proof-of-concept code. Browsers are a particularly attractive target for attackers, since nearly every computer owner uses one, they contain a seemingly unlimited number of bugs, and attacks can sometimes be perpetrated without the user's knowledge through drive-by downloads.

The only remedy offered by Secunia was to avoid untrusted Web sites, and not to open ZIP or image files from other dubious locations.

Apple was notified of some of the vulnerabilities in January, others in February, but has not yet patched any of them, claimed Ferris.

Apple didn't immediately reply to a request about how it plans to deal with the zero-day bugs; typically, the Cupertino, Calif. computer maker refuses to comment on unresolved or unpatched security vulnerabilities.

E-mail This Story
Print This Story
Reprint This Story




Get the latest Developer news, product info, and trends every week.


Related Content

  Right-click and choose Copy to extract RSS Feed URL  Developer Pipeline's Main RSS Feed
  Right-click and choose Copy to extract RSS Feed URL  Developer Pipeline's Blog RSS Feed




Editorial and vendor perspectives






Editor's Picks
Special Report: Are Computers Destroying The Earth?
With Earth Day just around the corner, two reporters cross swords over the question of whether computers and technology are helping or hurting the environment. See what they have to say, then vote on who's got it right.

Embedded Experts: Fix Code Bugs Or Cost Lives

Apple's Boot Camp: Macs Do Windows

Microsoft Platforms Chief Talks Co-opetition With Open Source

Crash Course: Get a Handle on Web Services Specs and Standards

How do recent stories highlighting the ability of Apple's new Intel-based Macs to run Windows as well as Mac OS X affect your view of Macs as development platforms?
Macs that can run Windows and OS X? Gimme!
    39%
Yawn. No thanks.
    22%
It all comes down to price point. Count me as maybe.
    17%
Ha. If it doesn't run zOS or Solaris, forget it...
    12%
Apple? Never! TRS-80 RULEZ!
    10%

Product Finder
E-fficiency: Web App IDEs
Want to give your e-business a competitive edge? Turbo-charge your development projects with one of these Web application development IDEs.

Web Site Development Made Easy

A "Class" Act: Software IDEs





DEVELOPER PIPELINE MARKETPLACE (sponsored links)