OS X vulnerability allows superuser access to hackers
Another vulnerability has popped up in OS X, and this time it's not Java-related. The developers of Metasploit, a software utility that makes it easier for people to abuse vulnerabilities in OSes for security-testing purposes, have added a new Unix Sudo vulnerability to their software. As OS X runs a modified version of Unix, this means it is vulnerable. As Arstechnica reports:
The authentication bypass vulnerability was reported in March and resides in a Unix component known as sudo. While the program is designed to require a password before granting "super user" privileges such as access to other users' files, the bug makes it possible to obtain that sensitive access by resetting the computer clock to January 1, 1970. That date is known in computing circles as the Unix epoch, and it represents the beginning of time as measured by the operating system and most of the applications that run on it. By invoking the sudo command and then resetting the date, computers can be tricked into turning over root privileges without a password.
Apple has not commented on the bug, but the company is usually pretty quick to issue a fix once it is aware of them.
Subscribe to Newsletter
Software Updatesmore updates
- Spotify update adds equalizer, refreshed Artist page and more
- Fantastical 2.1 for iOS adds new snooze, search and notification features
- ExpanDrive 4, more services and faster sync
- Apple adds iTunes Extras to Apple TV
- Spotify updates with new iPhone controls in time for summer BBQs
- iTunes U update will bring course creation and student discussion to iPad app