CVE-2007-0015 and reliable attack vectors

| No Comments | No TrackBacks

CVE-2007-0015 on Mac OS X Tiger 10.4.6

When CVE-2007-0015 was published by the Month of Apple Bugs team, their exploit used a QTL Quicktime playlist file for triggering the bug. Whether their decision was because of preventing the exploit from being used "en masse" or simply for testing a different, less classic attack vector, it's still worth noting that it could have worked far more efficiently via Safari, since Quicktime supports embedding playlist files and the Safari process address space would be easily subverted to ensure a higher degree of reliability when executing our payload.

Sometimes it's good to remember old flaws, and improve old exploit code. Sometimes it's even better to use new attack vectors on old flaws, too.

No TrackBacks

TrackBack URL: http://www.subreption.com/mt/mt-tb.fcgi/89

Leave a comment

About this Entry

This page contains a single entry by Subreption LLC published on April 6, 2008 8:04 PM.

Memory locking behavior issues was the previous entry in this blog.

Linux kernel developers silently patching issues? No way! is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.