also @ TechSpot: Rumor: AMD "Piledriver" FX CPU production to begin Q3 2012

Vulnerability discovered in OS X and Safari

By

On February 22, 2006, 11:55 AM EST

A security flaw has been discovered in Mac OS X that can result in a system being compromised, even if updated with the latest available patches. Secunia has posted a security advisory detailing the nature of the exploit, which stems from incorrect handling of meta data in various file types:

The vulnerability is caused due to an error in the processing of file association meta data in ZIP archives (stored in the "__MACOSX" folder) and mail messages (defined via the AppleDouble MIME format). This can be exploited to trick users into executing a malicious shell script renamed to a safe file extension stored in a ZIP archive or in a mail attachment.
It's also possible to become compromised just by visiting a particularly crafted site with false files, making this type of exploit rival similar ones found in IE and Windows. Hopefully a patch will be made available soon, and make sure to keep your OS updated.

Related Stories

No tags on this story

User Comments (1)

Post a comment
DragonMaster
on February 22, 2006
5:44 PM
Now that Microsoft had a lot of problems discovered lately, it's Apple's turn?

Reply

Browse more commented news

Post a new comment

Guest user

To post as an anonymous
user click here
.

Members

If you are a TechSpot member,
please login first.


By signing up you gain complete access to the TechSpot community. Join thousands of computer and technology enthusiasts that contribute and share knowledge in our forum. Post messages, get a private inbox, upload your own photo gallery and more.

Subscribe to TechSpot

Get free exclusive content, learn about new features and tech breaking news.