The Register®

Biting the hand that feeds IT

Vuln exposes soft underbelly of Mac OS X

Apple patch pending

Details of a vulnerability in Mac OS X that creates a mechanism for crackers to take over vulnerable machines has been posted on the Net.

Security researcher William Carrel released details of a vulnerability, and suggested workarounds, in advance of a fix from Apple because of what he sees as the vendor's sluggish response to the problem.

The issue stems from a flaw in Apple's Dynamic Host Configuration Protocol (DHCP) client that means a user can be tricked into logging onto a rogue server. DHCP servers manage the assignment of IP addresses on a network.

If an Apple machine is booted in a hostile environment, this vulnerability means an attacker could load malicious code and take full control of a vulnerable Mac OS X workstation or server.

Exploitation is possible in both wired and wireless environments but by far the greater risk appears to come with WLANs.

The vulnerability affects Mac OS X 10.2 and 10.3 on both workstation and servers. Earlier versions of Mac OS X may also be vulnerable.

Carrel suggests a number of workarounds including preventing any network authorisation services from obtaining settings from DHCP, as explained here.

A fix from Apple is not expected before next month at the earliest. ®

Related Stories

Apple preps second Panther OS update
Panther bitten by second data damaging bug
Scripting flaws pose severe risk for IE users

Free report. "Comparing Data Center Batteries, Flywheels, and Ultracapacitors: What is the best energy storage for you?"

Don’t Miss

Warning: roadworksNetbooks and Mini-Laptops

Buyer's Guide They're little and we love 'em. But which ones are best?

Warning: roadworksIntel shakes AMD's chip-fabbing baby

Cross-licensing custody battle

Emails show journalist rigged Wikipedia's naked shorts

Overstock's Byrne vindicated amidst economic meltdown

Warning StopYours truly, angry mob

Book extract Bringing Nothing To The Party: Cleaning up the net, one satirical vigilante page at a time