MacDailyNews - Where Mac news comes first

 MacDailyNews Poll

Deal of the Day

5 Day Most Commented

Opinion Archive

Current Headlines

Latest Joy of Tech

  • Latest Joy of Tech!

MacNN

AppleInsider

Macworld UK

TUAW

MacRumors

Yahoo! Finance AAPL

iTunes Top 10 Albums

Mac OS X Downloads

Sun, Mar 21, 2010 - 07:26 PM EDT  —  AAPL: 222.2499 (-2.4001, -1.07%)  |  NASDAQ: 2374.41 (-16.87, -0.71%)

Apple Mac OS X/Safari DMG vulnerability debunked
Friday, December 01, 2006 - 01:10 PM EDT

The Apple Mac OS X "com.apple.AppleDiskImageController" Memory Corruption Vulnerability" isn’t a security flaw at all, let alone a critical, highly critical, or warn-everyone-via-the-BBC type event," Alastair J. Houghton reports for Alastair's Place.

Houghton reports, "Now, I should say, that I’m wary of suggesting that disk images are totally safe. There’s a lot of code involved in mounting and reading/writing a disk image, and quite a bit of that runs in kernel mode. But I am pretty peeved at the way that this issue has been so widely publicised, attracting a great deal of attention for lmh and MoKB, when in actual fact there is no such security flaw."

The Apple Mac OS X "com.apple.AppleDiskImageController" Memory Corruption Vulnerability" is nothing more than a "bug that causes a kernel panic. Not a security flaw. Not a memory corruption bug. Just a completely orderly kernel panic. There aren’t even any processor exceptions involved; the path to the panic is perfectly normal non-exceptional code using ordinary function calls," Houghton reports.

Full article here.

[Thanks to MacDailyNews Reader "Macaday" for the heads up.]

Related articles:
BBC covers Mac OS X ‘DMG bug’ - sort of - November 27, 2006
Mac OS X/Safari DMG vulnerability reported: Turn off automatic opening of ‘safe’ files to prevent - November 21, 2006

Bookmark and Share

Always -- Free ground shipping with orders over $50 at the Apple Store.

Reader Feedback: = registered.
Unregistered users: Feedback from multiple usernames are subject to deletion. Off-topic and posts from suspected astroturfers will be removed.

Reader feedback page 1 of 1 pages:
Dec 01, 06 - 02:15 pm Comment from: rasterbator

kernel panic! at the disco

Dec 01, 06 - 02:16 pm Comment from: G-Spank

Hey its the BBC, so right there you know they are biased.

Dec 01, 06 - 02:18 pm Comment from: macromancer

kernel panic in the library with the candlestick.

Dec 01, 06 - 02:18 pm Comment from: wandering joe

The flaw's a bug, now aint that a kicker. I'm a happy Mac user once again....

Dec 01, 06 - 02:19 pm Comment from: Sad sad sad

FUD is not what it was before. It was needed days and days of heated discussion to finally uncover FUD machines at work as they actually were: BS.

It is getting faster. Good.

FUD put to rest. Still, remains the issue: When idiotic pundits will stop to be fear mongers with Apple users community?

Dec 01, 06 - 02:21 pm Comment from: Jimbo von Winskinheimer

In fact, Colonel Panic was recently demoted after this incident. He's now only Major Panic.

Dec 01, 06 - 02:22 pm Comment from: The MacDaddy-Oh!

My bag of Jiffy-pop popcorn experienced a kernel panic one time in the microwave. Tough stuff to watch...

Dec 01, 06 - 02:26 pm Comment from: repoman23

"kernel panic! at the disco"

let's groove...

Dec 01, 06 - 02:58 pm Comment from: coolfactor

So, if it's "just a normal bug", is he saying that it doesn't give elevated privileges to an attacker?

Apple will have this squashed in an update. And until then, unless someone out there actually tries to exploit this, there's nothing to worry about.

Dec 01, 06 - 03:02 pm Comment from: gmeance

why is there a link to an AOL service that doesn't even support macintosh computers on this site???

Dec 01, 06 - 03:05 pm Comment from: Kaji

gmeance,

Not every visitor to this site is using a Mac... yet.

Dec 01, 06 - 03:11 pm Comment from: Right

Kajl,

Then its a good thing that they don't know when you click on the AOL ad with a default Mac setup you get, "Player is not supported by macintosh" that would sure make them stick with their PC a little longer. Oops.

Again, why is there a link to AOL on this site?

Dec 01, 06 - 03:11 pm Comment from: tune zang

where's zune tang? I need some laughs!

Dec 01, 06 - 03:22 pm Comment from: ChirssyOne

Personally I'm plagued by a lot of Private Panics.

Dec 01, 06 - 03:25 pm Comment from: in any case

It's still a denial of service attack, in a sense.

Dec 01, 06 - 03:30 pm Comment from: Michael

"In fact, Colonel Panic was recently demoted after this incident. He's now only Major Panic."

Good one Jimbo, laughed my butt off!

LOL

Dec 01, 06 - 03:47 pm Comment from: maccam

Just hope he's not promoted to General Panic!

Dec 01, 06 - 03:50 pm Comment from: gamer

get a CLUE - it was Colonel Panic up the bunghole with a candlestick

Dec 01, 06 - 03:50 pm Comment from: bearman

Jimbo, I laughed my butt off too. I just put it back on. But, don't change your day job yet. You must repeat atleast three times before I will become your agent. LOL

Dec 01, 06 - 04:27 pm Comment from: Dave

I just read through the full article and followed the link over to the MoKB blog site. The dialogue that comes out of Imh is pathetically childish and incredibly condescending. He spends more time name calling than he does supporting his claims.

He obviously does not know what he's talking about and has an incredibly hard time with anyone questioning him.

Perhaps behind closed doors he's Private Panic.

Dec 01, 06 - 04:30 pm Comment from: Real IT guy

"So, if it's "just a normal bug", is he saying that it doesn't give elevated privileges to an attacker?"

sigh. A kernel panic brings the whole system to a crashing halt, it's the Mac version of BSOD.

Ain't NOBODY got elevated privileges then.

Dec 01, 06 - 04:41 pm Comment from: maczealot

This also means that BBC's journalistic integrity is also debunked, regardless what code of ethics and standards of professionalism they purport to observe.

Dec 01, 06 - 04:59 pm Comment from: RC

The BBC's "journalistic integrity" has been down in the gutter along with CBS and others of that ilk that like to create slanted "news" stories for quite some time now, so this is certainly no surprise.

Dec 01, 06 - 05:28 pm Comment from: Zune Tang

I wish I had a pretty kernel panic instead of an ugly blue screen.

Welcome to the social.

Dec 01, 06 - 05:39 pm Comment from: john

Huh, I had a feeling that someone would come along and tell us what we already knew. It seems that most of these so called security flaws are just flawed reports by people who think they can fool us or something. The facts always prove otherwise. tongue wink

Dec 01, 06 - 05:42 pm Comment from: john

A denial of service attack is when many computers flood your network until it cannot communicate anymore. A kernal panic is a system error and that's all it is.

Dec 01, 06 - 05:46 pm Comment from: john

Wikipedia Definition of Denial of Service attack.
* Force the victim computer(s) to reset or consume its resources such that it can no longer provide its intended service.
* Obstruct the communication media between the intended users and the victim in such that they can no longer communicate adequately.

I don't see either of these happening with a simple disk image kernal panic error.

BBC report is so full of it. FUD that is.

Dec 01, 06 - 06:37 pm Comment from: Thorin

I have had two kernel panics since using OS X (2001).

Both occured while waking the machine from sleep.

G4 dual 867 1gb, 160gb, 10.4.8.

Dec 01, 06 - 07:07 pm Comment from: Macaday

Interesting that you raise the BBC's journalistic integrity..

Believe it or not, I have it in writing that they only published this news item because of the 'smugness of Mac users over security..'

You can be assured that was not allowed to rest.

Dec 01, 06 - 08:15 pm Comment from: DOS

"* Force the victim computer(s) to reset"

"I don't see either of these happening with a simple disk image kernal panic error."

Doing somehting which causes the OS to panic would be a classic Denial of Service attack.

Dec 01, 06 - 08:48 pm Comment from: radiomoscow

yeah biased BBC
im sticking with FOX they neva lie

Dec 02, 06 - 12:30 am Comment from: John Lange

Don't be too hard on "the Beeb". You can imagine how many hits they would get if they could work up a good article on "the virus that is going to wipe out all Macintoshes woldwide on December 25". Think of it. The holy grail of the Mac bashers.

May 13, 09 - 03:42 am Comment from: dgdfgdfg

<a >travel</a>
<a >career</a>
<a >baby</a>
<a >love</a>
<a >wedding</a>

Reader feedback page 1 of 1 pages:

Always -- Free ground shipping with orders over $50 at the Apple Store.

Add Your Feedback:

Register or Login

Name:

Email: (optional)

Emoticons | Allowed HTML Tags

Remember my info   Notify me of follow-up comments?

Please enter the "MDN Magic Word" you see in the image below: