Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Information-Security-News
[Top] [All Lists]

[ISN] Darwin flaws survive in Apple's Mac OS X

Subject: [ISN] Darwin flaws survive in Apple's Mac OS X
Date: Wed, 19 Jan 2005 01:55:30 -0600 (CST)
http://news.com.com/Darwin+flaws+survive+in+Apples+Mac+OS+X/2100-1002_3-5540955.html

By Robert Lemos 
Staff Writer, CNET News.com
January 18, 2005

A source-code audit of the open-source operating system from which
Apple Computer borrowed much of the code for Mac OS X revealed four
vulnerabilities of varying severity in Apple's software, a security
company said Monday.

The flaws in Darwin affect Mac OS X version 10.3--dubbed Panther--and
are caused by memory errors in the kernel, according to an advisory
released by ImmunitySec, the security company that found the flaws.

"In terms of criticalness, this kind of bug mostly affects remote
systems with multiple users," said David Aitel, founder and security
consultant with ImmunitySec, adding that since Mac OS X is most often
used on the desktop, the flaws will not be overly important on most
people's systems.

The company originally found the flaws in June and published them to
a private list of customers but did not notify Apple. It published the
flaws on Monday, after presenting them at a seminar.

Apple confirmed that it had not been told of the flaws and said it was
analyzing the vulnerabilities but would not elaborate.

ImmunitySec found the flaws by analyzing the publicly available source
code of the Darwin operating system, which implements a variant of
Unix known as BSD. Darwin forms the core of Apple's modern Mac OS X
operating system, and the flaws found by the security company also
affected Apple's operating system.

The flaws include a bug in Mac OS X's SearchFS function, several
kernel memory overflows and a logic bug in the AT command, which is
used to schedule tasks by the operating system.



_________________________________________
Open Source Vulnerability Database (OSVDB) Everything is Vulnerable - 
http://www.osvdb.org/

<Prev in Thread] Current Thread [Next in Thread>
  • [ISN] Darwin flaws survive in Apple's Mac OS X, InfoSec News <=