|
|
|
![]() |
Vulnerability Note VU#346656Apple Mac OS X fails to properly handle corrupted Universal Mach-O BinariesOverviewA vulnerability in the way Apple Mac OS X handles corrupted Universal Mach-O Binaries may result in execution of arbitrary code or denial of service.I. DescriptionApple Mac OS X uses the Mach-O file format's ability to support more than one type of machine code to create Mac OS X Universal binaries. Apple Mac OS X contains a vulnerability in the way corrupted Universal Mach-O Binaries are handled. According to Apple Security Update 2007-003:An integer overflow vulnerability exists in the loading of Universal Mach-O binaries. This could allow a malicious local user to cause a kernel panic or to obtain system privileges. This has been described on the Month of Kernel Bugs web site (MOKB-26-11-2006). This update addresses the issue by performing additional validation of Universal binaries. We are aware of publicly available proof-of-concept code that demonstrates this vulnerability. II. ImpactA remote, unauthenticated attacker may be able to execute arbitrary code with kernel privileges or cause a denial of service.III. SolutionUpgradeApple has published Mac OS X 10.4.9 for Mac OS X 10.4 (Tiger) systems and Security Update 2007-003 for Mac OS X 10.3 (Panther) systems in response to this issue. See Apple Security Update 2007-003 for more details.
References
This issue was reported in Month of Kernal Bugs MOKB-26-11-2006 by LMH. This document was written by Chris Taschner.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||