Sunday | 31 August, 2008
Computerworld
Warnings sounded over serious Apple flaws
Matthew Broersma (Techworld.com) 14/03/2006 07:41:58

Computerworld Buyer's Guide - Vendors Matched to this Article
Related Features
  • +

    Your World. . . Hacked 02/10/2007 10:51:23

    As your business becomes more collaborative and global, the risks to your company’s trade secrets rise proportionally. Fortunately, there are new strategies to protect the data that allows you to compete
    The call to Bob Bailey, an IT executive with a major US government contractor, came on an otherwise ordinary day in October 2003. "Why are you attacking us?" demanded the caller, an IT leader with a Silicon Valley manufacturer. He wanted to know why Bailey's company had launched a denial-of-service attack against his network
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualisation technologies, products, news and features.
RSS Feeds

Security company, EEye has warned of two serious bugs in Apple media software, putting both Windows and Mac OS X systems at risk.

The new reports follow a string of security warnings this year that threaten to end the widespread perception that Apple's software is relatively secure.

EEye last week reported two separate flaws affecting QuickTime and iTunes, both allowing attackers to potentially execute malicious code on a system.

Both affect Mac OS X as well as Windows NT, Windows 2000, Windows XP and Windows 2003, according to eEye, and both are rated as "high" severity. One flaw is the result of a heap overflow, and the other is caused by an integer overflow.

The company added both bugs to its roster of upcoming advisories, which alert users to flaws that have been discovered but not yet patched or publicly disclosed. EEye doesn't give details on such flaws, in order to allow users time to react and software vendors time to issue patches.

The oldest vulnerability on the list is currently a bug affecting Windows that was reported 153 days ago and hasn't yet been patched, eEye said.

Since the beginning of this year, Mac users have begun to experience a taste of the paranoia that has long afflicted Windows users. Recently, two viruses appeared targeting the OS X platform in the space of a week.

These were shortly followed by the public disclosure of code exploiting a severe OS X bug that could allow the Safari web browser to automatically execute malicious code on a system if users view a specially crafted site. The bug also affected OS X's built-in Mail e-mail client.

Antivirus vendors, who have long had difficulty selling their products to Mac users, have said attackers' new interest on the Mac is partly spurred by Apple's switch to the Intel platform. "It shows increased activity and viability for future Macintosh-based threats on the Mac OS X platform," said Ken Dunham, director of the rapid response team at iDefense, a Versign company, in a recent interview.

He pointing out that the last major Macintosh threat was the Autostart worm in 1998. "As a result, many Macintosh users are more likely to be complacent toward computer security and therefore are more likely to be vulnerable to any future threats that emerge against the Macintosh operating system," he said.

Computerworld Buyer's Guide - Vendors Matched to this Article
More about Intel, iDefense, Apple
Market Place

Computerworld Member Login


 

Prioritizing Services with IT Service Management (ITSM)

Computerworld Live Webinar
Wednesday 20th, August 2008
11:00am EST (Sydney, Australia)

To be repeated on:

Thursday 4th, September 2008
11:00am EST (Sydney Australia)

Sign up and receive a free copy of The Forrester WaveTM Service Desk Management Tools, Q2 2008 at the conclusion of the Webinar.

Attend and discover:

  • How to deliver value to your business through ITSM
  • Best practice ITSM implementation
  • Why emphasis is changing from optimizing IT management processes to better servicing customers and demonstrating real dollar value
  • If service-oriented ITSM is best for your business
Whitepaper

Enterprise Wireless WLAN Security

Learn more about the security challenges to be faced when defining and implementing security mechanisms within diverse wired and wireless network environments. Download this must-read guide to plan your wireless data protection strategy now.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links