ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

Mac OS X glitch published after patch 'delay'

Patrick Gray ZDNet Australia

Published: 27 Nov 2003 09:40 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Details of an as-yet-unpatched security vulnerability in Apple's OS X software have been published on the Web.

The researcher who found the vulnerability, William Carrel, claims he was forced to release his advisory to the public before the development of a patch, in the interests of Apple users -- users he says have been "left exposed" by the company's sluggish response in developing a fix.

He said Apple reneged on an agreed patch release date, then made him wait for weeks for the company to engineer a fix.

"Meanwhile, users are left exposed and independent rediscovery [of the vulnerability] seemed fairly likely... maybe by someone less scrupulous than myself," he wrote in the advisory. "I felt I was being strung along and that the issue may never get properly addressed so I set a hard deadline at that point. They didn't meet it, and I issued my advisory."

Apple drew fire from the wider security community last month when it failed to provide a patch for its older "Jaguar" versions of its OS X operating system, affectively forcing customers to buy an upgrade to the company's latest version of OS X, or "Panther", to secure themselves against a series of security glitches discovered by US-based security research firm @Stake.

While it has since been reported that Apple has issued a patch to correct the security defects in Jaguar discovered by @Stake, a close inspection of the recently released security update has revealed the Common Vulnerability and Exposure (CVE) candidate numbers listed for the patched vulnerabilities do not match the numbers assigned to the vulnerabilities discovered by @Stake -- thus it would appear OS X Jaguar variants remain vulnerable to the older bugs.

The latest vulnerability exploits weaknesses in the way the operating system handles malicious responses from rogue DHCP servers -- network servers which assign IP addresses to computers on a network.

Carrel published his advisory 48 days after initially notifying Apple Computer of the bug, he claimed in the advisory. "It would not be fair of me to let Mac users hang out in the breeze for more than two months on an issue of this magnitude. You may disagree, but I have no regrets about my actions and feel that I was more than fair to Apple Computer and its users," he wrote.

One security researcher, who declined to be named, told ZDNet Australia the "news behind the news is that people are starting to poke at Mac OS X now. Apple finally has an OS that is fun for hackers to play with".

Apple has indicated it will release a patch in December, Carrel said. Workarounds for the vulnerability are detailed in the advisory.

Apple Computer was unavailable for comment at the time of writing.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with Konica

Did you find this article useful?
294 out of 413 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Sentry Posts Blog

Virtual Teams: Small Business Innovati...

Virtual Teams: Small Business Innovation Author: Eric Everson, Founder – MyMobiSafe.com As the founder of MyMobiSafe.com, I’ve found that because of our presence in the industry... More

Post a comment

Mobile Security and Innovation: An Ope...

Mobile Security and Innovation: An Open Case Author: Eric Everson, Founder MyMobiSafe.com The times are changing in the mobile industry as “big wireless” in the US Markets are calling... More

Post a comment

Government launches new e-crime unit

Ok, so this is outside of my main area of focus of sustainable and green tech but I do track some security issues too. I was at a meeting last week with Microsoft's security advisor... More

Post a comment