Newsletter:

Skip Navigation LinksHome > News > Security > Apple patch overlooks Mac OS X 10.3

Apple patch overlooks Mac OS X 10.3

By Tom Sanders
4 October 2006 10:06AM
Tags: apple | patch | overlooks | mac | os | 10

Older version of OS left open to local privilege escalation.

Apple's OS X 10.3 continues to suffer from a security vulnerability which the vendor repaired on newer versions of the operating system last Friday, a posting on the milw0rm security exploit site has warned. 

The flaw is identified as CVE-2006-4392. It affects the Mach exception ports which handle kernel errors in OS X.

A malicious user with access to a system could use the flaw to execute unauthorised code in privileged programs. This effectively provides attackers with root access, allowing them to install applications and change system settings.

Apple released a patch on Friday that repairs 15 vulnerabilities in OS X 10.4. But it fails to address the Mach vulnerability in OS X 10.3, according to the milw0rm posting.

The posting also provides code demonstrating how to exploit the vulnerability.

Because exploiting the flaw requires access to a system, it primarily concerns shared systems in schools and libraries, for instance, as well as users who provide guest accounts over the internet.

Apple had not responded to requests for comment at the time of going to press.

Copyright © 2008 vnunet.com

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 


Tripwire - Click here to win an iTouch





Product Reviews

Star Rating
The AdventNet Manage-Engine Password Manager Pro provides a complete system for password management in one...
Star Rating
The Cyber-Ark Enterprise Password Vault, or EPV, is a high-end password management powerhouse.
Star Rating
The Hitachi ID-Archive sets its focus on password randomisation.
Star Rating
The Lieberman Software Enterprise Random Pass­word Manager is a full-on password manager and randomiser for...
Star Rating
Proginet SecurForce is a little bit of a horse of a different color for this month's Group Test.
Unified Communications Podcast Centre

TopTopics
(6679) -  internet
(6423) -  iinet
(6397) -  copyright
(6397) -  afact
(5994) -  servers
(5994) -  mipi
(4847) -  telstra
(4534) -  broadband
(4470) -  nbn
(3010) -  internode
(2534) -  microsoft
(1888) -  network
(1492) -  software
(1469) -  data
(1372) -  google