heise Uncovers Leopard DoS Flaw
by , 10:30 AM EST, December 10th, 2007
heise Security revealed on Monday that Apple's Mac OS X 10.5 operating system contains a security flaw that could allow an attacker to crash the system through a denial of service attack. The threat could allow an attacker to cause a kernel panic by taking advantage of an integer overflow when processing certain Mach-O binaries.
Macs with only one user account should be immune to potential attacks. For multi-user setups, however, the threat could be exploited even if the user doesn't have administrative level access because it does not require special privileges.
heise claims the flaw exists in Mac OS X 10.4.11, 10.5, and 10.5.1, and that Apple has not yet issued a fix. There are no know instances of this threat being used.
Observer Comments
According to the article:
"Single user systems should not be at risk as the bug can only be exploited by users logged onto a system."
You have to already be logged on to the system to cause a problem. If I have direct authorized access to a system, I can do all kinds of things to it. I suppose this ought to be fixed, but I don't see it being a very serious problem before it does get fixed.
Recent Headlines - Updated January 9th
- Thu, 5:56 PM
- Macworld Expo 2009 - Orbicule Announces Undercover 3 with Location Technology
- 5:49 PM
- News - TOM BIHN, Waterfield Designs Release 17” Unibody MacBook Pro Notebook Cases
- 3:50 PM
- Macworld Expo 2009 - Targus Shows File Share Cable for Mac
- 3:40 PM
- Macworld Expo 2009 - Blackmagic Demonstrates Video Recorder
- 3:14 PM
- News - Microvision Demonstrates SHOW WX Laser Projector
- 2:53 PM
- Just a Thought - First Time: A Closer look at Macworld and San Francisco
- 12:35 PM
- News - Mac Gamers Can Now Fight For Good or Evil in City of Heroes
- 12:12 PM
- News - EVE Online to Expand the Known Universe in March
- 11:53 AM
- News - Feral to Ship Rome: Total War Gold in March
- 11:19 AM
- News - Freeverse Says Commander: Napoleon at War is on the March
- 10:34 AM
- News - Whither Macworld Expo?
- 9:47 AM
- News - Paragon Issues 30 ‘Talking’ Dictionaries
The Mac Observer Reader Specials
- Download Typestyler, still the Ultimate Styling Tool for Internet, Print and Video Graphics. Works great in Classic with a Native OS X Version on the way. Free Tryout: www.typestyler.com
New MacPro Memory 800Mhz With Apple Spec Heat Sink - 2GB $62 / 4GB $82 / 8GB $158. Click to Maximize your Macs...
Mac observers can now play Party Poker for Mac as well as Mac casino games by going to MacPokerOnline.com.
RamJet Memory: Upgrade a MacBook to 4GB RAM for $99! Add a 320G MacBook Hard Drive for $73! MacBook Pro 17" 8GB Kits Available Now! Click hereFor the latest Apple products use Ciao a comparison website to find laptops like MacBook Air. Then find the best prices on MP3 players and use our comparison tool to evaluate cell phones.
Laptop Hardware Provided by TechRestore - Overnight Mac & iPod Repairs.

