The Mac Observer

Skip navigational links

Featured Article: Just a Peek - StoryMill

FrSIRT Reports Mac Denial of Service Flaw

by , 8:20 AM EST, November 27th, 2006

The computer security watchdog group FrSIRT is reporting a new potential security threat to Mac OS X that could result in a denial of service attack. The threat takes advantage of a flaw in the kevent() function when registering certain kernel events and allows local unprivileged users to cause the system to panic.

The attack requires direct access to the affected computer, so the threat of theft or physical vandalism is probably greater than the potential for a denial of service attack.

This security threat impacts Mac OS X10.4.8 and earlier, and Apple has not yet released a security update to fix the issue. It is considered low risk, and there are currently no known instances of the exploit being used.

Digg!

Observer Comments

Show: Subjects Only | Full Comments
Close Name:Guest
Subject: Danger. Security flaw allows denial of service

An undocumented security flaw in Macintosh computers allows an attacker to perform a denial of service by removing all the key caps from your keyboard. This attack requires direct access to a the affected computer.

Apple suggest superglue.

Close Name:horvatic Posts: 102 Joined: 27 Jun 2003
Subject: This threat is beyond low it's more like buried

I would hardly call this a threat when you need direct access to the system. This so called threat is beyond low it more like buried.

Close Name:Guest
Subject: Wait a second...

So they're saying that they've issued a warning about a Denial of Service attack vulnerability that can only be initiated at and only affects the local computer, and the result is a kernel panic?

Uh oh... the Mac is DOOOMED!

Close Name:Mikuro Posts: 457 Joined: 15 Jun 2002
Subject: Who said it was a big deal?

At least these people are actually being honest about this risk. They're not blowing it out of proportion like fear-mongers, the way most of these reports do.

A security hole doesn't need to be exploitable over the Internet to matter. For most home users, something that requires physical access isn't too scary, but in offices, schools, libraries, etc., it matters just as much as, if not more than, remote attacks.

Although as far as any kind of attack goes, causing a simple crash IS pretty ho-hum. You might as well just turn off the machine. *shrug* Definitely low-risk. When something like this makes it to a news site, you know the state of Mac security is pretty damned good.

Comment on this Article


You cannot edit your comments.   You cannot delete your comments.
Log in | Register | Having Problems? Reset TMO Cookies & Try Again
Username:   Password:   Log me on automatically each visit   

You are not logged in, and this post will appear as "Guest." Log in with your username and password from the TMO forums. If you do not have a username, you can register here.
Please note that guests are limited to including a maximum of two URLs per post.


Post A Comment
  Subject


  Your Comments



Please enter the word exactly as you see it in the image above. Registered users aren't prompted for this. Having trouble reading the image get a new one.


Recent Headlines - Updated Friday, November 21st, 2008

Fri., 7:15 PM
iPO Free on iTunes - Photography Specials
6:35 PM
Khronos Group Shows Off OpenCL Standard
5:15 PM
John Martellaro's Blog: StrangeCharm - HD, DRM & iTunes
4:30 PM
iPO iPhone Gaming News - EA Reveals Plans For SimCity on iPhone
4:00 PM
Psystar Lawsuit Filings Reveal Potential Document Policy Problems at Apple
2:40 PM
Mac Gaming News - Puzzle Adventure Game Book of Legends Comes to the Mac
2:20 PM
TMO's DealsOnTheWeb.com - Philips 8.5" Widescreen Portable DVD Player With iPod Dock: $129.99 Delivered
12:05 PM
The Simplified Guide to Buying a New HDTV System
10:20 AM
PopChar X 4.1.1 Improves FreeHand 10 Support
9:35 AM
iPodObserver - Apple Rolls out iPod touch Software 2.2 with Podcast Downloads
8:55 AM
New Mac Malware Surfaces
8:35 AM
Apple Releases Pro Applications Update 2008-004
8:00 AM
iPO Review - Clusterball Arcade
7:35 AM
iPodObserver - iTunes 8.0.2 Improves VoiceOver, More
6:55 AM
iPodObserver - iPhone Software 2.2 Adds Google Street View, Podcast Downloads
 

The Mac Observer Reader Specials

  • Special Report: iPhone
  • __________
  • Help TMO Grow
  • Macworld Expo - Hotel Deal
  • Podcast: Mac Geek Gab
  • Podcast: Apple Weekly Report
  • TMO on Twitter!

Apple Stock Quote

  • AAPL: $82.58. Change Today: +2.09.
  • (Prices delayed up to 20 minutes.)
  • Discuss in our Apple Finance Board

Hot Topics

Apple iTunes

Top Deals From DealsOnTheWeb