|Skip to Main Content|
  1. PROSPECTIVE STUDENTS
  2. CURRENT STUDENTS
  3. FACULTY & STAFF
  4. ALUMNI
  5. COMMUNITY & FRIENDS
 
  1. CAMPUS LINKS
    1. Inside UNCG
    2. Admissions
    3. Academics
    4. Libraries
    5. Administration
    6. Research & Centers
    7. International Programs
    8. Continuing Education
      & Outreach
    9. Technology
    10. Arts & Entertainment
    11. Employment
    12. Corporate Resources
    13. Giving to UNCG

Information Technology Services

Home » News » 2009 » June » OS X Vulnerability

Critical Vulnerability in Mac OS X

19 June 2009

FastFacts

  • Who: Faculty, Staff, Students (Mac Users Only)
  • What: Vulnerability in the OS X operating system
  • Client Action: Download and install the latest update via Software Update

CRITICAL: Apple Mac OS X Java Pointer Dereference Remote Code Execution Vulnerability

Affected:

Description: The Java Runtime Environment installed by default on Apple Mac OS X contains a remote code execution vulnerability. The error is due to improper validation of input to "apple.laf.CColourUIResource" constructor. The first argument to this constructor, which is a long integer, is interpreted as pointer to a C-object. Successful exploitation may allow an attacker to execute arbitrary code on the vulnerable installations, with the privileges of the logged on user. Attacker will have to entice the user to visit the malicious page to carry out this attack.

Status: Vendor confirmed, updates available (Download and install the latest update via Software Update).

References:

If you have questions or need more information, contact 6-TECH at (336) 256-TECH (8324) or 6-TECH@uncg.edu.



 
Information Technology Services
The University of North Carolina at Greensboro

Greensboro, NC 27402-6170
Technical Support 336.256.TECH (8324)