On BNET: 6 strategies to beat Internet addiction
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: May 5, 2004 12:16:00 AM

A researcher has again taken Apple Computer to task for not adequately labeling the seriousness of the security flaws described in its advisories.

Patches for five vulnerabilities released Monday fix various components of the Mac OS X operating system. The greatest threat is a buffer overflow in the Apple file-sharing system that could allow a remote attacker to take over control of the system. But the company described it as a correction "to improve the handling of long passwords."


Get Up to Speed on...
Enterprise security
Get the latest headlines and
company-specific news in our
expanded GUTS section.


"They are not characterizing the issue so that people can make a security decision about it," said Chris Wysopal, vice president of research and development at @Stake, a digital security firm that found the flaw and reported it to Apple. "It seems they think that everyone will update their computers all the time, and that is not the way the world works."

Most security companies normally classify a remotely exploitable software flaw as a "critical" vulnerability.

Wysopal is the second researcher in a week to criticize Apple for downplaying the vulnerabilities in its system. eEye Digital Security, the company that found a flaw in Apple's QuickTime multimedia player in February, also claimed that Apple is not properly characterizing vulnerabilities.

Apple said the flaw in the QuickTime movie player for Mac OS X could cause the player to crash. "Playing a malformed .mov (movie) file could cause QuickTime to terminate," the company stated in an advisory it published late Friday afternoon.

However, eEye said a movie file could be created that would cause malicious code to execute when the user opened the file.

"We told them that if you are not able to execute code, then talk to us, so we can show you the issues," said Marc Maiffret, chief hacking officer at eEye.

An Apple representative could not be reached for comment.

Four flaws, including the flaw in the AppleFileServer, affect Mac OS X 10.2.8, also known as Jaguar. All five flaws affect Mac OS X 10.3.3, or Panther.

  • Talkback
  • Most Recent of 91 Talkback(s)
eLurker, choose your diagnosis.
I understand that you are too stupid to talk about computers.

So, a simpler task for you:

G.W. Bush told that he attacked Iraq because Saddam had WMD and will attack any country who supp... (Read the rest)
Posted by: Vily Clay Posted on: 05/12/04 You are currently: Logged In as: a Guest  | Login | Terms of Use
Sloppy journalism  Rick_K | 05/04/04
your right....  JoeMama_z | 05/04/04
Not downplaying...  Rick_K | 05/05/04
im sorry  JoeMama_z | 05/05/04
Correction  tic swayback | 05/05/04
but apache is included on the install CD?  JoeMama_z | 05/05/04
Answer  mabricen | 05/05/04
Install CD  PA-ITGuy | 05/05/04
PA-ITGuy--But that's what Apple is doing  tic swayback | 05/05/04
To: swayback - oops  PA-ITGuy | 05/05/04
Because..  mabricen | 05/05/04
With you knowledge of OS X, you should be sorry  Rick_K | 05/06/04
Who cares???  theace18 | 05/04/04
Biased?  adamparker | 05/05/04
Biased???  PA-ITGuy | 05/05/04
eEye, eEye, oh!  buddhistMonkey | 05/05/04
But...  PA-ITGuy | 05/05/04
culture clash  buddhistMonkey | 05/05/04
buddhistcockroach  nikoli | 05/06/04
Not Quite True  shade51 | 05/05/04
Wrong  issthatso | 05/05/04
Apache vs. IIS  PA-ITGuy | 05/05/04
Finaly a revelation  mabricen | 05/05/04
yep  eLurker | 05/05/04
Keep getting "tired" then  nikoli | 05/06/04
Excelent point  mabricen | 05/05/04
look at the history...  ryusen | 05/05/04
Apple criticized for existing  mlindl | 05/05/04
Really?  shade51 | 05/05/04
I think it's that animosity, you were talking about.  Rick_K | 05/05/04
why am I surprised?  PA-ITGuy | 05/05/04
I was responding to his question.  Rick_K | 05/05/04
Nothing personal  PA-ITGuy | 05/05/04
No problem  Rick_K | 05/05/04
Beauty is in the eye...  amicus_curious | 05/05/04
Whining  shade51 | 05/05/04
More and more people...  Rick_K | 05/06/04
Microsoft criticisms veiled in positive actions  mlindl | 05/05/04
Quicktime flaw  PA-ITGuy | 05/05/04
Re: Quicktime flaw  ndelc | 05/05/04
re:  eLurker | 05/05/04
major leagues  ryusen | 05/05/04
You are absolutley right..  mlindl | 05/05/04
All I can say is  PA-ITGuy | 05/05/04
are you serious?  ryusen | 05/05/04
actually...  ryusen | 05/05/04
Zdnet, no Apple stories, unless iPod  FilledOut | 05/05/04
meanwhile, virus infested Windows boxes are costing industry millions  jellyclock | 05/05/04
As they save the users billions  amicus_curious | 05/05/04
Are you kidding?  mlindl | 05/05/04
Incredible!!!  amicus_curious | 05/05/04
Excuse me  TWRX | 05/05/04
Cox? is that you?  el1jones | 05/05/04
No, I'm not, but...  amicus_curious | 05/05/04
PR copy or personal opinion ?  jellyclock | 05/05/04
*nix users being ignorant  eLurker | 05/05/04
Architecture offers some protection  tic swayback | 05/05/04
tic - of course  eLurker | 05/05/04
You have part....  mabricen | 05/05/04
which part was that? (nt)  eLurker | 05/05/04
They cost users, not save  cuervo-gold | 05/05/04
Macs  Protector | 05/05/04
Re: Macs  ndelc | 05/05/04
Macs work here  gfeier | 05/05/04
Good Laugh of the Day.  middle of nowhere | 05/05/04
*sigh*  ryusen | 05/05/04
windows  sherpard@... | 05/09/04
Doesn't matter because Mac OS Sucks  Protector | 05/05/04
Re: "Doesn't Matter..."  fuchikoma | 05/05/04
re  Protector | 05/05/04
Comparison  voska | 05/05/04
so...  eLurker | 05/05/04
Big differences  tic swayback | 05/05/04
not my point  eLurker | 05/05/04
Trolls  tic swayback | 05/05/04
shills  eLurker | 05/05/04
He's not a linux troll  Rick_K | 05/05/04
rick_k: see my response below (nt)  eLurker | 05/06/04
Actually  Linux User 147560 | 05/05/04
How creative!  cuervo-gold | 05/05/04
vinnym; the windows troll  Rick_K | 05/05/04
ummm ... no; wrong conclusion on your part  eLurker | 05/06/04
Isn't that the definition of a troll?  Rick_K | 05/07/04
hmmm  eLurker | 05/10/04
He does display trollish attributes  Rick_K | 05/11/04
interesting  eLurker | 05/11/04
eLurker, choose your diagnosis.  Vily Clay | 05/12/04
Well, at least the beige boxes were less expensive  FilledOut | 05/05/04
Macs don't suck at all,  FilledOut | 05/05/04
Notice  Spin_Masterz | 05/05/04
.. wow..uh huh etc.,  404 | 05/06/04

What do you think?

advertisement
Click Here