Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror
×
OS X Operating Systems Bug Security

Month of Apple Fixes 177

das writes "On the same day as the launch of the Month of Apple Bugs (MOAB) (blog), Landon Fuller, a programmer, Darwin developer, and former engineer in Apple's BSD Technology Group, has launched an effort to provide runtime fixes for each MOAB issue as they are released. A fix has already been posted for the first MOAB issue."
This discussion has been archived. No new comments can be posted.

Month of Apple Fixes

Comments Filter:
  • by daveschroeder ( 516195 ) * on Tuesday January 02, 2007 @05:34PM (#17435922)
    Kevin Finisterre, security researcher, founder of Digital Munition [digitalmunition], and co-presenter of the Month of Apple Bugs [info-pull.com], has also responded on the SecurityFocus focus-apple list [securityfocus.com] to some of my concerns [securityfocus.com], expanding on some of the motivations and reasoning behing MOAB (followup [securityfocus.com]).

    Also, the second bug was just posted a few minutes ago: a udp:// URI handling vulnerability in VLC Media Player [info-pull.com] that affects both the Mac OS X and Windows versions of VLC Media Player. While not exactly what I'd call an "Apple bug" (yes, yes, I know the FAQ says they're also looking at "popular applications" that run on Mac OS X as well), it is interesting to note that vulnerabilities in cross platform applications may transfer more easily to the Intel-based Macs running Mac OS X...

    In any event, Apple's immediate technical response and longer-term strategic response to MOAB should be interesting.

    (Disclaimer: I am the story submitter.)
  • PR for Vista launch (Score:0, Interesting)

    by Anonymous Coward on Tuesday January 02, 2007 @05:57PM (#17436192)
    Whats this guys motivation? He says specifically in his FAQ that he did not tell Apple of these problems, he just releasing it publicly.

    Rarely, the point is releasing them without vendor notification. Although, sometimes we may decide to pass an issue through the appropriate people. The problem with so-called 'responsible disclosure' is that for some people, it means keeping others on hold for insane amounts of time, even when the fix should be trivial. And the reward (automated responses and euphemism-heavy advisories) doesn't pay off in the end.

    So why do we have to wait an entire month to get to bug #31. Whats the motivation to keep bug #31 alive for 31 more days?

    Also from the FAQ:


    7. John Doe has written a 'post' in his blog, saying he debunks the XXX bug, what's that?

    No worries. It's probably someone begging for attention or PR-brainwashed


    Thats right, anybody who disagrees is psycho. Is that you George?
  • privsep? (Score:3, Interesting)

    by emil ( 695 ) on Tuesday January 02, 2007 @06:00PM (#17436216)

    I realize that the idea is just catching on in IE and has not been implemented anywhere else, but why doesn't Safari setuid() the rendering engine to guest (or some other nonprivileged user)?

    Is this feature in the works? I certainly hope so.

  • by SuperKendall ( 25149 ) on Tuesday January 02, 2007 @06:15PM (#17436370)
    From the other thread, it appeared that no Mac owner posted saying that they had been able to replicate the results - the people that did post results said the quicktime file given crashed Quicktime, but did not run the payload target. Simply being able to crash an application is not the same as actually executing arbitrary code.
  • by porkchop_d_clown ( 39923 ) <mwheinz@nOSpAm.me.com> on Wednesday January 03, 2007 @12:17AM (#17439690)
    In the sense that it affects Apple machines, sure.

    But, yeah, it's kind of weak. If this is the best they can come up with, Apple can rest easy.

"It's a dog-eat-dog world out there, and I'm wearing Milkbone underware." -- Norm, from _Cheers_

Working...