Skip to main content

Mac security under renewed question

posted onApril 17, 2009
by hitbsecnews

Heise Security has confirmed the effectiveness of a privilege escalation exploit for Mac OS X. The result of mounting a maliciously formed HFS disk image file is that the user gains root privileges.

The exploit is one of several revealed at last month's CanSecWest 2009 conference by Christer Oberg and Neil Kettle. It could be used by someone that has legitimate access to a system with normal user privileges in order to carry out unauthorised activities that require admin rights.

The vulnerability is said to be present in all versions of Mac OS X from 10.4.0 onwards, including the Snow Leopard betas. Other Mac OS X vulnerabilities disclosed by Oberg and Kettle involve kernel memory leaks and/or denial of service conditions.

Source

Tags

Apple

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th