Several of these bugs were patched several months ago by Linux distros. Reported months before that.
Which means that Apple is hanging their customers out to dry while specific vulnerability information is public.
The libpng vulns are especially concerning. Anyone who wanted to exploit OS X could have done that using these "arbitrary code execution" bugs. Did they?
Apples OS X does very, very little (compared to other OSes) to prevent exploitation of vulnerabilities. No sensible ASLR, no proper sandbox, nada, zilch.
Discussion on:
Message 14 of 1
The best of ZDNet, delivered
ZDNet Newsletters
Get the best of ZDNet delivered straight to your inbox



