BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] OSX Mavericks root exploit, and Safari
- Subject: [Discuss] OSX Mavericks root exploit, and Safari
- From: bogstad at pobox.com (Bill Bogstad)
- Date: Fri, 17 Apr 2015 21:14:31 +0200
- In-reply-to: <55314D55.5080702@gmail.com>
- References: <BY1PR0401MB164105D69C780D97CCE5F051DCE30@BY1PR0401MB1641.namprd04.prod.outlook.com> <55314D55.5080702@gmail.com>
On Fri, Apr 17, 2015 at 8:13 PM, Richard Pieri <richard.pieri at gmail.com> wrote: > On 4/17/2015 9:26 AM, Edward Ned Harvey (blu) wrote: >> >> I'd like to alert people that OSX Mavericks has a root exploit that >> will not be fixed. All Mac users must immediately update to Yosemite >> in order to maintain any semblance of security. > > > Cutting through the hyperbole.... > > It's a local privilege escalation vulnerability nicknamed rootpipe. It can > be mitigated by doing one thing: don't run as an administrator account. > Standard user accounts cannot be used to exploit this vulnerability. >From the Ars Technica article linked from the original email: "... The researcher continued to experiment with the flaw until he found a way to elevate privileges even from standard OS X accounts, which give users considerably less control. To Kvarnhammar's amazement, he was able to expand the attack by sending a what's known as a "nil" to the OS X mechanism that performs the elevation authorization. A nil is a zero-like value in the Objective C programming language that represents a non-existent object. ...." Sounds like your info might be out of date. Bill Bogstad
- Follow-Ups:
- [Discuss] OSX Mavericks root exploit, and Safari
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] OSX Mavericks root exploit, and Safari
- References:
- [Discuss] OSX Mavericks root exploit, and Safari
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] OSX Mavericks root exploit, and Safari
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] OSX Mavericks root exploit, and Safari
- Prev by Date: [Discuss] OSX Mavericks root exploit, and Safari
- Next by Date: [Discuss] OSX Mavericks root exploit, and Safari
- Previous by thread: [Discuss] OSX Mavericks root exploit, and Safari
- Next by thread: [Discuss] OSX Mavericks root exploit, and Safari
- Index(es):