All the latest UK technology news, reviews and analysis

New Mac OS X exploit disclosed

by Shaun Nichols

More from this author

12 Jan 2007

Comment: 1

  • Tweet this
Apple security flaw
Security researchers have posted exploit code for a bug in Apple's Safari browser

Security researchers have posted exploit code for a Mac OS X vulnerability that runs through Apple's Safari web browser. 

A successful exploit could allow for remote code execution, according to the original posting of the vulnerability. Security firm Secunia gave the vulnerability its second-highest rating of 'highly critical'. 

The vulnerability was disclosed by a security researcher known only as 'LMH' as part of the Month of Apple Bugs project which aims to disclose a new Mac OS vulnerability every day in January. 

The exploit uses a default feature in Safari originally designed to streamline the download and launch of files.

By default, Safari allows for several types of files to be opened automatically, including disk image (.dmg) files which are often used to compress applications for download.

The vulnerability lies in the way Mac OS X processes disk images. A specially crafted .dmg file could cause an application crash that would leave the attacker free to execute malicious code.

The vulnerability can be mitigated by turning off the 'Open safe files after downloading' option in Safari's preference panel, according to Secunia.

'LMH' released code for a similar exploit in November which also used the 'Open safe files' feature in Safari to launch .dmg files that targeted another vulnerability in OS X. 

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

97%

1%

1%

0%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Inside Sales / Fluent French / London / 30K TO 35k 10K OTE /

Inside Sales / IT Sales / Business Development / Fluent...

Senior Web Developer / Engineer (HTML, JavaScript, CSS)

Title: Senior Web Developer / Engineer (HTML, JavaScript...

Java Developer (J2SE / JEE)

Job Title: Java Developer (J2SE / JEE) Salary: up to...

Agile Test Manager

Job Title: Agile Test Manager Salary: up to 55k per...

To send to more than one email address, simply separate each address with a comma.