There were two demos: One on 10.4.6 showing that it was vulnerable (crash achieved and remote code execution is possible). The second demo showed no crash on 10.4.8 showing that the patches Apple released did indeed fix the problem he pointed to.
Maybe, but that doesn't explain the emails that were shown between him and Apple engineers pointing to problems in Mac products in early August of last year.
http://erratasec.blogspot.com/2007/03/apple-infoan d-thats-all-folks.html
There were two demos:
One on 10.4.6 showing that it was vulnerable (crash achieved and remote code execution is possible).
The second demo showed no crash on 10.4.8 showing that the patches Apple released did indeed fix the problem he pointed to.
Maybe, but that doesn't explain the emails that were shown between him and Apple engineers pointing to problems in Mac products in early August of last year.
http://erratasec.blogspot.com/
Its not a buffer overflow, its just unvalidated input.
I liked it, it was Segals best movie in years.
Hey, it was better than hackers.