You are here: silicon.com > Software > Operating Systems

Operating Systems

OS X vulnerability posted before Apple patches

"It would not be fair of me to let Mac users hang out in the breeze for more than two months on an issue of this magnitude."

By Patrick Gray

Published: 27 November 2003 08:05 GMT

Details of an as-yet-unpatched security vulnerability in Apple's OS X software have been published on the web.

The researcher who found the vulnerability, William Carrel, claims he was forced to release his advisory to the public before the development of a patch, in the interests of Apple users -- users he says have been "left exposed" by the company's sluggish response in developing a fix. He said Apple reneged on an agreed patch release date, before stringing him along for weeks while he waited for the company to engineer an update.

"Meanwhile, users are left exposed and independent rediscovery [of the vulnerability] seemed fairly likely... maybe by someone less scrupulous than myself," he wrote in the advisory. "I felt I was being strung along and that the issue may never get properly addressed so I set a hard deadline at that point. They didn't meet it, and I issued my advisory."

Apple drew fire from the wider security community last month when it failed to provide a patch for its older 'Jaguar' versions of its OS X operating system, affectively forcing customers to buy an upgrade to the company's latest version of OS X, or 'Panther', to secure themselves against a series of security glitches discovered by US based security research firm @Stake.

While it has since been reported that Apple has issued a patch to correct the security defects in Jaguar discovered by @Stake, a close inspection of the recently released security update has revealed the Common Vulnerability and Exposure (CVE) candidate numbers listed for the patched vulnerabilities do not match the numbers assigned to the vulnerabilities discovered by @Stake - thus it would appear OS X Jaguar variants remain vulnerable to the older bugs.

The latest vulnerability exploits weaknesses in the way the operating system handles malicious responses from rogue DHCP servers - network servers which assign IP addresses to computers on a network.

Carrel published his advisory 48 days after initially notifying Apple Computer of the bug, he claimed in the advisory. "It would not be fair of me to let Mac users hang out in the breeze for more than two months on an issue of this magnitude. You may disagree but I have no regrets about my actions and feel that I was more than fair to Apple Computer and its users," he wrote.

One security researcher, who declined to be named, told silicon.com sister site ZDNet Australia the "news behind the news is that people are starting to poke at Mac OS X now. Apple finally has an OS that is fun for hackers to play with."

Apple has indicated it will release a patch in December, Carrel said. Workarounds for the vulnerability are detailed in the advisory.

A representative of Apple Computer was unavailable for comment at the time of writing.

Patrick Gray writes for ZDNet Australia.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

for IT White Papers Newsletter

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
IT Operations Support Analyst, Citrix, Oracle, Wins, Avaya, London SW

The user community is in excess of 1,500 people, across 40+ sites in the UK, Europe, The Gulf, USA, Australia and the Far East. The main technologies ...

Mac/PC Support Engineer –Mac OSX, Adobe, Quark, Windows, Server 2003, AD

KEYWORDS : Mac OSX, Windows, OSX Server, ARD, Support, Macintosh, Windows Server, Quark Express, Adobe, MS Office, Extensis Suitcase, FTP, Carbon ...

Technical Support Engineer - French Speaking

Brands & technologies, and Vulnerability Network Scanners ( Nessus, nmap, Cybercop, ISS Internet Scanner). Windows 2000, Windows NT, Novell, Lotus ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: