Wi-fi hijack risk for Macs

Patchy Apple...

NEWS

A trio of security flaws in Apple software that runs wireless-networking hardware could allow Macs to be hijacked over wi-fi, Apple said on Thursday.

The Mac maker released security updates to repair the problems, which together affect the AirPort wireless driver in Mac OS X 10 Panther version 10.3.9 and Mac OS X Tiger 10.4.7, according to Apple's security alert. Both Intel-based and Power PC-based versions of the Mac operating system are affected, on regular computers as well as on servers, it said.

Apple said in the alert describing one of the flaws: "Attackers on the wireless network may cause arbitrary code execution." "Arbitrary code execution" means the intruder can commandeer the system. The other two flaws allow the same type of compromise but can also cause system crashes or, in one case, privilege escalation, it added.

There are no known exploits for the vulnerabilities addressed by the update, Apple said. This means Mac users should not be under immediate threat of attack.

Apple's security patches come a month after security researchers at SecureWorks demonstrated at the Black Hat security confab how an attacker could gain complete control over a laptop by sending malformed network traffic to a vulnerable computer. They showed a video of a successful attack on an Apple MacBook.

The researchers used a third-party wireless card in the MacBook for their demonstration but said the AirPort wireless technology built into the laptop was also vulnerable, creating controversy in the Apple community.

In a statement released after Black Hat in August, Apple critiqued SecureWorks for saying Macs were insecure. A company representative said at the time: "Despite SecureWorks being quoted saying the Mac is threatened, they have provided no evidence that it is."

But Apple's security patches are not related to the Black Hat presentation, a company representative said on Thursday. Instead, the company itself hunted for bugs in its wireless software and uncovered the vulnerabilities, according to the representative.

The representative said: "In August, SecureWorks approached Apple with a potential flaw that they felt could affect wireless drivers on Macs. They did not supply us with any information to allow us to identify a specific problem, so we initiated an internal audit.

"Today's update pre-emptively strengthens our drivers against potential vulnerabilities, and while it addresses issues found internally by Apple, we are open to hearing from security researchers on how to improve security on the Mac."

A SecureWorks representative did not have an immediate comment.

The three vulnerabilities addressed by Apple all have to do with how the AirPort wireless driver handles "frames". An attacker could exploit the flaw by crafting a malicious frame and making it available on a wireless network used by vulnerable Macs, Apple said.

The first of the flaws, identified by CVE-2006-3507, affects Power Mac, PowerBook, iMac, Mac Pro, Xserve and Power PC-based Mac Minis equipped with wireless capabilities. The second issue, identified by CVE-2006-3508, impacts Intel-based Mac Mini, MacBook and MacBook Pro computers equipped with wireless. CVE, or common vulnerabilities and exposures, is a list that provides an index of standardised names for vulnerabilities.

The third problem, identified by CVE-2006-3509, is specific to how the AirPort wireless driver interacts with third-party wireless software, according to Apple. It also impacts Intel-based Mac Mini, MacBook and MacBook Pro systems equipped with wireless.

Apple did not list the iBook on its list of affected systems but it also did not mention the iBook as one of the machines not affected by any of the three flaws.

The Mac OS security updates are available via Apple's software update utility in the operating system, and from Apple's download site. Only one update is required, and the utility will present the applicable fix, Apple said.

Joris Evers writes for CNET News.com

Comments

There are 2 comments. Join the discussion

  1. 1. Chris Anderson

    What no "Another Mac bashing article" comments from the Apple zealots, are They all unwell?

    • 25 September 2006 11:54
    • Add comment
  2. 2. Simon

    Why should it provoke a storm of protest ? For a change it's a sensibly written factual piece - instead of the ill-informed "oh dear, a security update, look how crap Macs are" articles we've become used to from much of the press.

    But lets look at the facts, this is update 5 of this year, and we're nearly to the end of September. What's the score with Windows ? Even if you roll up all their patches released on any date into one, that's still one a month plus the non-scheduled ones - so at least 10 updates for a product which in theory is more mature than OS X 10.4 (as it's been released for longer and so had more time for bugs to be fixed).

    Compare the severity as well. This is one where you HAVE to be in close proximity in order to send wireless packets. So no hacking attempts from the other side of the world !

    • 25 September 2006 13:06
    • Add comment

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your silicon.com account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy.

Questions about membership? Find the answers in the Membership FAQ

Get silicon.com's daily newsletter

  • Register on silicon.com

    Enter your email to register

Keep in touch with silicon.com

silicon.com newsletters