Linked by Thom Holwerda on Fri 20th Mar 2009 13:51 UTC, submitted by google_ninja
Thread beginning with comment 354151
To view parent comment, click here.
To read all comments associated with this story, please click here.
To view parent comment, click here.
To read all comments associated with this story, please click here.
The real kicker, according to the same post, was the the bug Miller exploited has already been found and fixed upstream, but Apple is using an old version of that library that still has the bug.
And this is yet another clue for the retards who claim OS X is so f--king secure, why on earth do they put a bunch of security fixes in "Security fix q1 2009" for instance? If they was serious about fixing the issues they would update/patch the issue immediately and release an update, but they don't. So you have plenty of unpatched stuff until they decide to release their big patch.




Member since:
2005-07-06
According to rumors on some other site I read the exploit wasn't in WebKit per se, but in a third party (open source) library used by the javascript engine. The real kicker, according to the same post, was the the bug Miller exploited has already been found and fixed upstream, but Apple is using an old version of that library that still has the bug.
Of course the only people who actually know what happened are under NDA, so take this with a grain of salt.