New Vulnerability in Mac OS

by chris 12/23/2007 11:26:53 PM

Well I wouldn't expect to see anything about this in the next "Hello I'm a PC, and I'm a Mac" commercials that my wife seems to find so hilarious so I decided to make sure I pointed it out...  SecurityFocus just published an article about a new vulnerability in the Mac OS that could cause some real heartache for the user community.  From the article:

apple_ad2

When OS X checks for new updates, it first contacts swscan.apple.com
to receive the XML catalog file. This file references the distribution
definition files, which can reside on another server. Software Update
receives these files and calls some of the JavaScript functions to check,
if the update is suited for the local machine.


The catalog file and the distribution definition files are both received
using HTTP without any authentication. By running a malicious update server,
it is possible to provide distribution definition files, which execute
arbitrary commands using JavaScript on the remote machine requesting the
update.

I think it's kind of ironic that in order to get the patch for this vulnerability you have to expose yourself to the actual vulnerability you are trying to protect yourself against.  In any case I'm not trying to rub Apple's nose in it...  This kind of thing can happen to every OS.

Add comment


(Will show your Gravatar icon)  

biuquote
  • Comment
  • Preview
Loading




Powered by BlogEngine.NET Theme by Mads Kristensen Hosted by 1and1 Hosting Sign in
The opinions expressed herein are my own personal opinions and do not represent my employer's view in any way. © 2008 Chris Blankenship

DSCODUC on Technorati  

Stop Spam Harvesters, Join Project Honey Pot   This work is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License  

Welcome to my blog

Welcome to my site

Villainy wears many masks,
none of which so dangerous as virtue…



LinkedIn   GeoURL

Recent Comments

Comment RSS

Wordle Gallery

Shelfari Book Library