Email us! Subscribe to Liquidmatrix!

Apple Mac OS X UDIF Memory Corruption Vulnerability

Well, it was only a matter of time before a major Mac vulnerability came out. It happens. Deal with it.

Move along folks…nothing to see here…move along.

From Secunia:

Description:
LMH has reported a vulnerability in Mac OS X, which potentially can be exploited by malicious, local users to gain escalated privileges or by malicious people to compromise a vulnerable system.

The vulnerability is caused due to an error in com.apple.AppleDiskImageController when handling corrupted DMG image structures. This can be exploited to cause a memory corruption and may allow execution of arbitrary code in kernel-mode.

The vulnerability is reported in a fully patched Mac OS X (2006-11-20). Other versions may also be affected.

Solution:
Deactivate the option “opening safe files after downloading” in the preferences and grant only trusted users access to affected systems.

Article Link

Tags: , , ,

Tag It:
  • Digg
  • del.icio.us
  • Slashdot
  • Technorati
  • SphereIt
  • StumbleUpon
  • Fark
  • YahooMyWeb
  • Furl
  • Spurl
  • Ma.gnolia
  • NewsVine
Related Articles:

  • ARCserver Tape Engine Memory Corruption
  • Winamp MP4 File Handling Memory Corruption Vulnerability
  • Internet Explorer Memory Corruption Vulnerability (again)
  • Microsoft Word Unspecified Memory Corruption Vulnerability
  • Apple Mail Command Execution Vulnerability
  • Leave a Comment