| Mac OS X Vulnerabilities from a Darwinian Birth |
|
|
|
| Written by Editor |
| Wednesday, 19 January 2005 19:45 |
|
The first vulnerability is a integer overflow that affects the ‘searchfs()’ system call which is Mac OS X specific system call for searching catalogs of HFS file systems. The second issue is a kernel stack overflow within the ‘semop()’ system call. The third issue are is a collection of kernel overflows which have been inherited from old BSD kernels versions. Finally the fourth issue is a logic error relating to the setuid binary /usr/bin/at, which allows non-root/non-admin users to read any file on the file system. For the full details of the vulnerabilities you can get the Immunity security advisory here. Meanwhile for Mac OS X users don’t forget to get the patch from Apple when it is available from Apple’s update service. |
| Last Updated ( Thursday, 14 September 2006 23:10 ) |













