Critical Mac flaws put users at risk
Apple is investigating several unpatched and potentially serious security flaws in Mac OS X that have been publicly disclosed, the company said on Friday.
Tom Ferris, a security researcher, late on Thursday published information on seven flaws in Apple's operating system, potentially putting Mac users at risk of a cyberattack. The most serious of the flaws could let attackers surreptitiously run malicious code on users' PCs, Ferris said in an interview via instant messaging.
"We're in the process of investigating and addressing them," Bud Tribble, Apple's vice president of software technology, told CNET.co.uk's sister site, News.com. "I think it is important to note that although these are potential vulnerabilities, there are no known exploits to them and they are not affecting customers today."
Five of the flaws identified by Ferris relate to how Mac OS handles various image file formats -- including BMP, TIFF and GIF, according to his security advisories. Another flaw is due to the way OS X decompresses ZIP archives. Additionally, Ferris claims to have found several bugs in Apple's Safari browser.
"The image flaws are the scariest ones, giving an attacker multiple methods of compromising a host," Ferris said. "They can be exploited to execute arbitrary code very easily and were not hard to find."
Apple silently fixed one of the flaws related to handling of TIFF image files in update 10.4.6, Ferris said. The other bugs remain unpatched, he said, adding that he reported the issues to Apple earlier this year.
Apple believes the public disclosure of security flaws doesn't help anyone, a position shared by most software makers. "We don't feel that our customers are better served by public disclosure of potential issues," Tribble said. "We think that in the general case, people who need to know about issues are the ones that can actually fix the bugs."
Ferris in the past has released information on flaws in several Apple products, including iTunes and QuickTime, as well as the Firefox Web browser, before an official patch was made available.
Security monitoring companies Secunia and the French Security Incident Response Team, or FrSIRT, deem the latest Mac OS X issues "highly critical" and "critical", respectively.
"Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by attackers to execute arbitrary commands or cause a denial of service," Secunia said in an advisory. The company recommends not surfing to untrusted Web sites and not opening suspect ZIP archives or images to protect against attacks.
Apple expects to address the issues in an upcoming security update, but could not say when that fix might be released. "Our target is to do it promptly," Tribble said. "How quickly that can be done depends on a lot of variables, in terms of how much information we get and how complex the things are to address."
More about Software
- Obama in sex video shocker? Oh wait, it's just spam September 11, 2008
- No black holes from Large Hadron Collider, say scientists September 10, 2008
- Michael Moore to premiere film online September 05, 2008
- Images: Touring Google's Chrome browser September 05, 2008
- Extensions promised for Chrome September 04, 2008

- Smart fortwo mhd: Lowest running costs of any small car?
- Honda Insight: World's cheapest hybrid car?
- Ferrari California: Sometimes roofless, never toothless
- LG unveils the LG-KP500: Keeps veiled all useful info
- LG 50PG6900: 50-inch plasma goodness with built-in Freeview+
- Photos: Chevy Volt electrifies Paris Motor Show

- Microsoft CEO Ballmer: Zune for Windows Mobile
- 'Oops I'm Late' app covers for you
- YouTube upgrade: Better uploader, 10x the file size
- Opinion: Why Yahoo Buzz will benefit Digg
- Living the D:Ream: Let's rename the Large Hadron Collider
- The 50 most significant moments of Internet history
- Google Android: Beyond the mobile phone
- Google to show UK religious group's anti-abortion ads
- Norton AntiVirus 2009: First Norton not to suck?
- Seismometer and Movies: Our favourite new iPhone apps
- Best of the forums this week: Why Earth hasn't imploded
- Hands-on with iTunes 8 Genius: Einstein with dementia?
- Apple iTunes 8: Just add Genius
- New Zunes: Buying songs from radio and more
- RealDVD: DVD ripping goes legal


