Slashdot Mirror


Apple Patches Massive Holes In OS X

Trailrunner7 writes with this snippet from ThreatPost: "Apple's first Mac OS X security update for 2010 is out, providing cover for at least 12 serious vulnerabilities. The update, rated critical, plugs security holes that could lead to code execution vulnerabilities if a Mac user is tricked into opening audio files or surfing to a rigged Web site." Hit the link for a list of the highlights among these fixes.

35 of 246 comments (clear)

  1. Twelve? by Spyware23 · · Score: 5, Informative

    Apple's own security update page (http://support.apple.com/kb/HT4004) lists these six, where did Threatpost author get the number 12 from?:

    Security Update 2010-001

    *

    CoreAudio

    CVE-ID: CVE-2010-0036

    Available for: Mac OS X v10.5.8, Mac OS X Server v10.5.8, Mac OS X v10.6.2, Mac OS X Server v10.6.2

    Impact: Playing a maliciously crafted mp4 audio file may lead to an unexpected application termination or arbitrary code execution

    Description: A buffer overflow exists in the handling of mp4 audio files. Playing a maliciously crafted mp4 audio file may lead to an unexpected application termination or arbitrary code execution. This issue is addressed through improved bounds checking. Credit to Tobias Klein of trapkit.de for reporting this issue.

    *

    CUPS

    CVE-ID: CVE-2009-3553

    Available for: Mac OS X v10.5.8, Mac OS X Server v10.5.8, Mac OS X v10.6.2, Mac OS X Server v10.6.2

    Impact: A remote attacker may cause an unexpected application termination of cupsd

    Description: A use-after-free issue exists in cupsd. By issuing a maliciously crafted get-printer-jobs request, an attacker may cause a remote denial of service. This is mitigated through the automatic restart of cupsd after its termination. This issue is addressed through improved connection use tracking.

    *

    Flash Player plug-in

    CVE-ID: CVE-2009-3794, CVE-2009-3796, CVE-2009-3797, CVE-2009-3798, CVE-2009-3799, CVE-2009-3800, CVE-2009-3951

    Available for: Mac OS X v10.5.8, Mac OS X Server v10.5.8, Mac OS X v10.6.2, Mac OS X Server v10.6.2

    Impact: Multiple vulnerabilities in Adobe Flash Player plug-in

    Description: Multiple issues exist in the Adobe Flash Player plug-in, the most serious of which may lead to arbitrary code execution when viewing a maliciously crafted web site. The issues are addressed by updating the Flash Player plug-in to version 10.0.42. Further information is available via the Adobe web site at http://www.adobe.com/support/security/bulletins/apsb09-19.html Credit to an anonymous researcher and Damian Put working with TippingPoints Zero Day Initiative, Bing Liu of Fortinet's FortiGuard Global Security Research Team, Will Dormann of CERT, Manuel Caballero and Microsoft Vulnerability Research (MSVR).

    *

    ImageIO

    CVE-ID: CVE-2009-2285

    Available for: Mac OS X v10.5.8, Mac OS X Server v10.5.8

    Impact: Viewing a maliciously crafted TIFF image may lead to an unexpected application termination or arbitrary code execution

    Description: A buffer underflow exists in ImageIO's handling of TIFF images. Viewing a maliciously crafted TIFF image may lead to an unexpected application termination or arbitrary code execution. This issue is addressed through improved bounds checking. For Mac OS X v10.6 systems, this issue is addressed in Mac OS X v10.6.2.

    *

    Image RAW

    CVE-ID

    1. Re:Twelve? by mjschultz · · Score: 5, Insightful

      Apple's own security update page (http://support.apple.com/kb/HT4004) lists these six, where did Threatpost author get the number 12 from?

      The Flash update is actually 7 vulnerabilities.

    2. Re:Twelve? by Graff · · Score: 5, Insightful

      The Flash update is actually 7 vulnerabilities.

      Moral of this story:
      Avoid Flash and you can cut the amount of vulnerabilities approximately in half!

  2. Must be running bootcamp by Anonymous Coward · · Score: 4, Funny

    The Apple commercials have told me that viruses and security holes are only possible in Windows, so I gather they are patching boot camp installs now

    1. Re:Must be running bootcamp by recoiledsnake · · Score: 3, Insightful

      It's interesting that many of these(like the image exploits) can be triggered by just browsing to a website(like the IE6/Google/China fiasco) or by mp4 audio/video files. Where are all the 'LOL M$ can't code' posters here?

      --
      This space for rent.
    2. Re:Must be running bootcamp by Anonymous Coward · · Score: 4, Funny

      No - the Apple commercials tell you that viruses are a problem for Windows. Viruses tend to find MacOS too arrogant an environment to survive in.

    3. Re:Must be running bootcamp by LihTox · · Score: 3, Insightful

      Viruses tend to find MacOS too arrogant an environment to survive in.

      Making our arrogance is an adaptive self-defense mechanism. So shove off, Windoze loser. :)

    4. Re:Must be running bootcamp by binary+paladin · · Score: 5, Funny

      LOL M$ can't code

  3. Re:I just patched a massive hole by Anonymous Coward · · Score: 5, Funny

    I'm afraid your patch provides insufficient coverage.

  4. A refund? by Monkeedude1212 · · Score: 5, Funny

    The only hole I want Apple to fix is the one they put in my wallet.

    1. Re:A refund? by jgtg32a · · Score: 4, Interesting

      buyers remorse?

    2. Re:A refund? by RocketRabbit · · Score: 3, Funny

      Probably not. The only folks I hear complaining about the cost of a Mac are the folks who haven't ever bought one.

  5. Re:Cover your eyes by amicusNYCL · · Score: 4, Insightful

    You just couldn't wait to post that, could you? FYI: every piece of software needs updates, and there is still always one piece of software that will be more secure than the others. I don't know if OSX is more secure than Windows 7, but both of them will continue to receive updates, that fact doesn't make either of them less secure.

    --
    "Our two-party system is like a bowl of shit looking at itself in a mirror." - Lewis Black
  6. Re:Security Well by amicusNYCL · · Score: 4, Funny

    You already posted that in the first comment anonymously, and it wasn't funny then either.

    --
    "Our two-party system is like a bowl of shit looking at itself in a mirror." - Lewis Black
  7. Re:Cover your eyes by e2d2 · · Score: 3, Insightful

    Windows 7 can still be targeted by a IE bug that's been in place since IE6. Safari doesn't have zero day bugs *that* old

    How would you know? Zero-day means a non-public exploit.

  8. image format bugs by phantomfive · · Score: 3, Informative

    Two bugs were found in their image libraries (arbitrary code execution bugs in TIFF and RAW-DMG). Makes me wonder if they even tested their image libraries at all when they were being written, because that kind of bug can usually be found in an image library by feeding it random data.

    --
    Qxe4
    1. Re:image format bugs by TrancePhreak · · Score: 3, Interesting

      Other companies got hit by those a long time ago and have since patched up their image libraries. Apple must have ignored it then and is now paying the price.

      --

      -]Phreak Out[-
    2. Re:image format bugs by Archaemic · · Score: 4, Informative

      Actually, I personally found and patched the TIFF bug. In January. Of last year. http://bugzilla.maptools.org/show_bug.cgi?id=1985
      Feeding random data (aka fuzzing) might work, but 99% of the time, I'd imagine it'd just give you a corrupted image and bail out. You have to be clever about how you search for it. I found a known vulnerability patch posted by, of all people, an Apple employee, and tried to reverse engineer what he'd fixed. I found that the patch hadn't been applied on old version of the PSP system software, which is what I was targeting. After messing with this specific attack vector, I noticed that I could still crash system software version that did have the patch. After reading up on LZW compression (which is what part of LibTIFF had the vulnerability) and the TIFF specification of how they implemented LZW, I realized that the Apple patch was incomplete--it only tested for one value you could give it that was erroneous. By simply changing the equality they used (in two places) to an inequality, I tested for all erroneous values. Meanwhile, I tried to exploit the new unpatched vector on the PSP so that I could inject code. Failing this, I decided the best course of action was to submit a bug report to LibTIFF. It might seem a tad unethical to try and exploit the bug before reporting it, but I wasn't trying to exploit in for malicious purposes, and not on a desktop operating system. Regardless, I failed to make it do more than crash the PSP. Surely the best course of action here would be to patch it upstream before anyone else found it. (Incidentally, this "arbitrary execution" this is blown out of proportion. In its current state, it is extremely unlikely that it could provide ANY code execution. Just crashing. Although I don't know if it's IMPOSSIBLE for it to execute code with this vulnerability, it would take a lot of work to get anything valuable out of this. Mostly it's a DoS. They usually just attach "arbitrary execution" when there's even the vaguest possibility for code to be executed, regardless of whether or not such an exploit has been demonstrated.)

      It, um, took a while for anyone to notice the patch. In fact, the only reason anyone did notice was because someone found some of the fruit of my research into this bug and then posted a link to the research in a new bug report. Funnily, they created a different patch, which, instead of preventing the infinite loop caused by the erroneous data, just tested to see if the loop was writing out of bounds. Perhaps both approaches should be used together. Defensive programming and all that. Regardless, I noticed this new bug report shortly afterward it was posted and pointed them back to the inexplicably ignored old bug report. Most Linux vendors applied the patch shortly after the new bug report was filed, but Apple lagged by a number of months, until 10.6.2 came out. This update backports the fix into 10.5.x. However, I've found that some projects (such as Qt) are still using ancient versions of LibTIFF that have had numerous bug and security fixes since they were last updated in the projects' trees. While Qt does try to use the system's version of Qt if it can, it's still kind of scary to think about what could happen if it falls back on its own version, as I've seen it do before when I try my "corrupted" TIFF on things like Arora.

      Incidentally, I am TAing a computer security course this semester. I guess previous experience helps.

  9. Re:Cover your eyes by AHuxley · · Score: 3, Interesting

    Anything posted on some forum, whispers in an irc chat?
    Anything new floating around for a Mac running 10.6 that will do an IE and pop the browser/OS from a remote site?
    Most still need the user to enter his/her password as a application/codec.
    Mac are still safe to surf with for now.
    Macs have a list of malware and loggers, the pre OS 10 had lots too.
    But nothing in the wild to infect just yet with a site visit.
    If anything existed outside law enforcement, spooks and one off professional solutions, every Mac AV vendor would have a youtube vid up.
    A link to buy protection at a fair price after the 2 to 3 mins of safari getting infected after following a link and their product saving the day.

    --
    Domestic spying is now "Benign Information Gathering"
  10. Re:Cover your eyes by Dumnezeu · · Score: 3, Informative

    No, it can't. Well technically, it can be exploited, but IE runs sandboxed in Win 7 so the exploiter can't really do much.

    --
    Yes, it's sarcasm. Deal with it!
  11. Re:Cover your eyes by jo_ham · · Score: 4, Informative

    But it is.

    And patching vulnerabilities that are found just makes it more so.

    Sorry, what was your point again?

  12. Re:Cover your eyes by tacarat · · Score: 5, Informative

    Saying that OSX is less secure due to these vulnerabilities is how MS said that Linux was less secure than windows. These aren't OS vulnerabilities, they're application vulnerabilities (well, for the programs I recognize as a non-Mac person). The OS itself is fine. The trick is, of course, that some of these things are included practically by default. So as we wouldn't count a problem with notepad as a Windows OS issue, so we shouldn't count ones for other OS's non-essential programs.

    That's not to say that Mac users have free license to ignore proper security practices. Trojans, poor/shared passwords and not updating their software can leave them as vulnerable, if less targeted, than PC users. Given that one of the problems is with flash (and the fix is as simple as an update), I wonder if there's a good enough of a target out there for hacking Mac WOW players through flash ads hijacks.

    Before you flame, I will say that if you're on /. and a Mac lover, I sincerely doubt you're one of the problem kids for updates on most any system you control.

    --
    "Common sense will be the death of us all"
  13. Different Day, Same Crap by His+Shadow · · Score: 4, Insightful

    Has anyone driven a truck thru these gaping holes? Anyone? Beuller? When OSX is suffering from a deluge of viruses from all these supposed gaping holes in it's Architecture, please come back and let us know. Because while every operating system has vulnerabilities, only Microsoft was kind enough to make those vulnerabilities accessible by system wide scripting mechanisms that allowed millions of computer users the world over be the subject of attacks from the hundreds of thousands of pieces of malware constantly fighting to infect Windows PCs. The count (for those who think a security vulnerability makes Apple's points about viruses invalid) is about one hundred thousand to 0. This is being very generous. So, yes, as a matter of fact, there are no viruses for Mac OS X. Not virtually none, not almost none. None.

    --

    Fiat Homos et Pereat Theos

  14. Re:Cover your eyes by chentiangemalc · · Score: 4, Informative

    With default Windows 7 settings, the current exploit doesn't work. IE8 in XP without DEP protection. It CAN theoritically be expolited with DEP but haven't seen any current exploits that work around DEP protection. Also running with non-admin privileges (recommended, and default in vista & windows 7) reduces the attack surface (i.e. backdoors can't be installed without taking advantage of some other vunerability) so the IE vunerability is a bit overblown, following good security practices (which are default in vista & windows 7) already prevent the known attacks.

  15. Re:You forget one simple thing... by jo_ham · · Score: 3, Insightful

    There aren't enough Windows with IIS installed to make the average script kiddie drool in anticipation in comparison to Linux/BSD with Apache. Oh wait.

    If you don;t think the the chance to be the "first person to exploit the 'secure' OS X with a virus" isn;t driving some of these people then you are deluded. Or that genuine organised crime isn't going after the Mac platform (as a non-negligable marketshare) as well as Windows since it is amulti-million dollar industry compromising machines over the net. So far though, not much beyond proof of concept stuff and things that require user credential authentication.

    It's no reason to be complacent (and the patching of vulnerabilities is not complacency), or the assertion that OS X is immune to threats, because it isn't. But it has proven to have a pretty good track record - not perfect, but pretty good. Continued work is still needed though.

  16. Re:Cover your eyes by EvanED · · Score: 4, Insightful

    So as we wouldn't count a problem with notepad as a Windows OS issue, so we shouldn't count ones for other OS's non-essential programs.

    Not saying you're in this group, but a lot of people around here have no problem counting IE vulnerabilities against Windows.

  17. Re:Cover your eyes by shutdown+-p+now · · Score: 4, Insightful

    So as we wouldn't count a problem with notepad as a Windows OS issue, so we shouldn't count ones for other OS's non-essential programs.

    So far as I have seen, problems with user-space components such as Notepad are indeed counted as Windows issues. Which makes perfect sense, since Notepad is present out of the box, and the box says "Windows" on it.

    Similarly, OpenBSD has a fork of Apache 1.3 in their base system. If a vulnerability is found in that, then surely it's an OpenBSD vulnerability (hence the difference between base system and ports).

    If Apple ships Flash plugin that way, then they have to deal with any security issues that may cause.

  18. "MASSIVE"? by jjoelc · · Score: 3, Interesting

    I just wonder why the summary title says "MASSIVE holes..." when the original article "serious".. a bit of bias, perhaps??

    More realistically, this is just another security update. Find me an OS that doesn't have them, and for similarly "obvious" or "easily found/fixed" (hindsight and armchair hacking being perfect of course) and I'll either switch right away, or dust off the old TRS-80 from my closet to run it on.

    The way I see it, if you have a brain and use it while browsing, you are generally fine. But people are stupid. And if you are going to market your product to stupid people, you need to make sure you do everything you can to minimize the damage stupid people can do to others. (Stupid people generally deserve their own damages...)

    Now to start the debate over which company is more in the business of marketing to stupid people...

  19. Re:Cover your eyes by DJRumpy · · Score: 3, Interesting

    You mean the one with cheaper/slower celeron with less L2 cache, slower DDR2 800 Mhz memory, a cheaper/slower integrated graphics solution, no firewire, a cheaper battery, mono audio speaker, VGA Out Only, no bluetooth standard, no Cam standard, and no optical digital audio output?

    Comparable specs?

  20. Re:You forget one simple thing... by jo_ham · · Score: 3, Informative

    Yes, my point about IIS vs Apache wasn't that there were more attacks against IIS, just that there are documented and exploited holes.

    And yes, there have been many holes found in the various parts of OS X that have been fixed (and some yet to be fixed) but in terms of malware in the wild, there is practically none. There was a disk image that claimed to be Office for Mac on torrent sites that actually ended up deleting your files after you gave it your admin password, and a couple of other proof of concept attacks, but stuff actually out there roaming free in the wild is extremely rare - vanishingly so. I will not say "none" because it is clearly not true, and it allows the possibility of something to emerge, but for all the holes that have appeared in components of OS X, over the course of the life of the OS, no one has demonstrated stuff beyond possibilities.

    The TFA does indeed say "could install spyware and delete files" - ie, if the hole is exploited. No one is denying that (and when the hole is closed, they can't) but so far, no one has been able to - the vector for attack has not been there. There was nothing in the wild that exploited some of these holes, and they have been nipped up before anything could be produced.

    There are obviously other holes that have yet to be closed - including, as some security people have claimed, ones that have been open and exposed for a very long time (consider the guy who knew of two vulnerabilities and kept one to himself so he could exploit it the next year at the 'break OS X contest'). If that hole was known and vulnerable for a year, where are the in-the0wild exploits actually installing malicious software and keyloggers and so on? The hole was there for a malicious mp4 file, but the malware that exploited it was not.

    I'm not not nieve enough to assume or assert that OS X gets a free pass on security, but the prior performance has been good compared to Windows, even with the difference in install base. It's in a similar position to Linux with regard to security holes (and shares holes with some BSD components that the OSS community is also exposed to).

  21. Re:Cover your eyes by TheRaven64 · · Score: 3, Interesting

    Well, except get access to the authentication credentials for my Internet banking site and transfer all of my money to a numbered Swiss account as soon as I log in. Good thing it can't get at my Freecell high scores though...

    --
    I am TheRaven on Soylent News
  22. Re:Cover your eyes by Lars+T. · · Score: 4, Informative

    The pwn2own contest would say otherwise. Mac is usually the first to go down.

    Because for pwn2own you need a zero-day exploit - how high are the chances to find a 0day for Windows and nobody else having it out in the wild until that one day in the year of pwn2own? OTOH, Charlie Miller was sitting on his last winner for over a year, and nobody else found that exploit during that year.

    --

    Lars T.

    To the guy who modded me down from perfect to terrible Karma - Apple haters still suck

  23. Re:Cover your eyes by DJRumpy · · Score: 3, Informative

    Not at all. Your only looking at the end result as evaluating risk from that, and not the vector of infection.

    The flash update wasn't 'dismissed' and I noted it was a serious issue, but the fault lies with Flash. It is an abomination.

    The MP4 vulnerability would require someone actually get their hands on a specifically crafted MP4. The typical user either creates their own MP4's from their own audio CD's, or downloads them from iTunes on a Mac. If they are getting them from seedy sources, then they pretty much get what they deserve

    The last one I wouldn't consider a huge risk simply for the fact that I had never heard of the format. It would require someone that works with raw image data who happens to get an Adobe DNG image that has this vulnerability. This isn't like some drive by hijacking. I don't see this as a likely path to infection.

  24. Re:You forget one simple thing... by mario_grgic · · Score: 3, Insightful

    What you are linking to is NOT a virus, but a malware that user has to download, authenticate themselves as someone allowed to install software and install it.

    If you have a user willing to do that, then all bets are off.

    The original assertion still stands though. No viruses (i.e. self propagating code that spreads from machine to machine without user intervention). There aren't any for OS X and I'm not aware of any for Linux/BSD etc either.

    --
    As the island of our knowledge grows, so does the shore of our ignorance.
  25. Re:Cover your eyes by Piquan · · Score: 4, Informative

    That's how most MP4s come into existence. But an MP4 (or a TIFF for that matter) can be put up onto a webpage by an attacker, and rendered by the browser without the user needing to explicitly download and run it. If visiting a maliciously-crafted website can lead to arbitrary code execution, I'd say there's a serious problem. (I haven't investigated the particular flaws closely enough to tell if that is the case. However, based on the advisory, it seems quite likely.)