Mac OS X Kernel Exploits
Immunity, Inc. has found several exploitable bugs in the Mac OS X kernel [PDF]. They allow a local, unprivileged user to escalate their privileges to root level. These are local security holes, meaning that a local user must be able to execute code on the vulnerable machine in order to exploit the holes. Not as serious a problem as remote security holes, but serious nonetheless.
The fixes are trivial, so I would expect to see an update from Apple shortly.
My favorite part of the security advisory? The disclosure paragraph:
This advisory has been released to the public, and may be reproduced only in its entirety
and only in OpenOffice format. This means you, if your name is Securityfocus,
Securiteam or Secunia.Looks like its dog-eat-dog in the security advisory business!
via MacSlash
By Chris on January 20, 2005 11:08 AM
| Permalink
