ITS Homepage Click here for text version of ITS homepage
Contact UAlbany Directories Calendars & Schedules Visitors Site Index Search
Admissions Academics Research IT Services Libraries Athletics
alerts_tag

Flaw in OS X could lead to system compromise


 

ALARM Group ALERT ¿ click for a description of ALARM, The Computing Alert System
Alert Number:  022406-01
Alert Date:  02/24/06
Alert Title:  Flaw in OS X could lead to system compromise
Update-to:  None
OS/Platform/Application: 
Apple Safari Web Browser running on Apple OS X
Apple Mail 2 on OS X
MAC OS X 10.4 (other versions may be vulnerable as well
Category:  ALERT
Severity:  MEDIUM
Attention:  Apple OS X System Administrators/Users, Desktop Support Personnel

Summary:  News of a recently-discovered (and potentially serious) flaw in the way Mac OS X v10.4 handles data files under certain circumstances has been published on several Internet Security resources and other media sources over the past few days.  In essence, the flaw may allow for malicious shell commands/scripts to be run on a victim machine through no user interaction other than visiting a specifically-crafted web page using the Safari Web Browser or opening an email message  using the Apple mail client (Using default Safari and mail client settings). 

At the time of this writing (12:15 EST 2/24/06):

(1) no active exploits for this vulnerability (in the form of malicious web pages, etc) are yet known to exist. 
(2) no vendor-supplied fix for the vulnerability has been released but several workarounds have been suggested by the Internet Security community.

Recommended Actions:  As a precautionary measure, Mac OS X administrators/users are encouraged to read the information below (see links in the "Resources" section) to gain a better understanding of the threat and risks associated with this vulnerability.  Apple Safari default preferences settings can be modified as a workaround to exploitation via web browser (See link below) and alternative applications such as Mozilla Firefox (web) and Thunderbird (mail) are being suggested by various security resources as another means of minimizing the risks associated with this vulnerability.

ITS Actions: At this time, ITS is taking no additional formal actions to address this issue.  An update to this alert will be issued if the situation changes and/or ITS elects to take additional actions.

Resources:

US-CERT Technical Cyber Security Alert Advisory:
http://www.us-cert.gov/cas/techalerts/TA06-053A.html

US-CERT Tutorial on altering Safari Default Preferences Settings (to minimize risk
of exploit):
http://www.us-cert.gov/reading_room/securing_browser/#sgeneral

SANS Diary of OS X Flaw:
http://isc.sans.org/diary.php?storyid=1138

Symantec Advisory:
http://securityresponse.symantec.com/avcenter/security/Content/16736.html?code=nlvirusbug24731

BBC News article on vulnerability:
http://news.bbc.co.uk/2/hi/technology/4739432.stm

USA Today article on vulnerability:
http://www.usatoday.com/money/industries/technology/2006-02-23-mac-security_x.htm

 

BLANKABCDEFGHIJKLMBLANK
BLANKNOPQRSTUVWXYZBLANK
CHOOSE FROM the ITS Site Index

GO TO an ITS Group

Information Technology Services
University at Albany, SUNY
1400 Washington Avenue
Albany, NY 12222
ITS Service Centers:  518-442-4000
 
University at Albany Home Page
Contact UAlbany | Directories | Calendars | Visitors | Site Index | Search
Admissions | Academics | Research | IT Services | Libraries | Athletics

Internet Privacy Policy              IT Policies