Wednesday, 25 October 2006

Mac OS X ftpd Buffer Overflow Vulnerability

Secunia Security is reporting that there is a venerability in Mac OS X 10.3.9 and 10.4.8 (though it may exist in other versio as well) that has the potential to allow remote execution of arbitrary code. The vulnerability is caused by an error that can ha en when ftpd glo characters, causing a buffer overflow.

Luckily the FTP service must be ru ing to be exploited, and OS X shi with FTP off by default. You can check your sharing preferences to make sure that you aren't ru ing FTP (and while you are there you might as well turn on the software firewall if it i 't currently ru ing).

[via the Mac O erver]

No comments: