Attackers could exploit the OS X vulnerability to install spyware or rootkits
Latest Apple flaw could allow attackers to compromise systems without any user interaction
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Critical flaw exposes Mac OS X users

Software's blind faith in Zip files puts users at risk

Tom Sanders in California, vnunet.com 22 Feb 2006
ADVERTISEMENT

A new critical threat to Apple's OS X operating system has surfaced that could allow attackers to compromise systems without any user interaction.

The flaw affects the way OS X handles meta data for Zip archives. The application considers the files to be safe and will automatically open them, allowing attackers to embed script code that the OS will execute without the user's knowledge.

Attackers could exploit the vulnerability to install software such as spyware or rootkits.

A system could become infected when users visit specially crafted websites or when saving any infected Zip archive. The attack requires no user interaction and uses the Terminal application, which is the OS X command shell.

Users of older versions of the operating system will first receive a warning asking whether they wish to execute the applications, but Apple removed this feature in the current 10.4 version of the operating system.

Security firm Secunia gave the flaw its highest rating of 'extremely critical', and said in an advisory that users can neutralise the threat by disabling the auto-run feature in the Safari browser. 

But the SANS Internet Storm Center later issued a warning that this workaround will fail fully to protect users.

See also:

The 'slurp.exe' application fits on a standard iPod'Podslurping' soon to be all the rage  20 Feb 2006
Combination of Apple PC and cello creates new kind of music  20 Feb 2006
The video glitch has come to light via Apple's discussion forumsWhite streaks could cause recall  10 Feb 2006

All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Cardiff, United Kingdom | University of Wales
Projects Officer - £26,665 - £30,912 - Cardiff The Projects Officer will work on specific projects under the direction of the Head of Information Services. It is expected that these will concentrate on the redevelopment ... more >
United Kingdom | Advent Computer Training
Are you stuck in a dead end job? Do you want to take control of your salary, life and career? Advent IT and computer training offers advanced, professional training and helps you find the right ... more >
London, United Kingdom | BP
Business Analyst - £ Competitive - London About BP Our business is the exploration, production, refining, trading and distribution of energy. This is what we do, and we do it on a truly global scale. ... more >
United Kingdom | Advent Computer Training
Are you stuck in a dead end job? Do you want to take control of your salary, life and career? Advent IT and computer training offers advanced, professional training and helps you find the right ... more >
More job opportunities