• Open Menu Close Menu
  • Apple
  • Shopping Bag
  • Apple
  • Mac
  • iPad
  • iPhone
  • Watch
  • TV
  • Music
  • Support
  • Search apple.com
  • Shopping Bag

Lists

Open Menu Close Menu
  • Terms and Conditions
  • Lists hosted on this site
  • Email the Postmaster
  • Tips for posting to public mailing lists
Re: Xcode 3.1 is available at connect.apple.com (Part 2b)
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Xcode 3.1 is available at connect.apple.com (Part 2b)


  • Subject: Re: Xcode 3.1 is available at connect.apple.com (Part 2b)
  • From: Bill Bumgarner <email@hidden>
  • Date: Sat, 12 Jul 2008 09:48:36 -0700

On Jul 12, 2008, at 9:36 AM, Jeff Johnson wrote:
A remote exploit for "/Library/Caches/com.apple.Xcode.503/ SharedPrecompiledHeaders/Cocoa-byhqthbdzrfwhagxhifeykxwodun/ Cocoa.h.gch"?

Not a remote exploit, but a local one. And, yes, that particular file is an attack vector, though far from the easiest one.


In particular, that location was more vulnerable to an attacker dropping a file in the cache that would cause the resulting build product to contain nefarious code, effectively turning a developer's application into a trojan.

/Library/Caches was read/write by all. /var/folders is owned by root and the subdirectories are the only part readable by your individual user, said subdirectories handed out by the system API. While it is still possible for it to be exploited as described, it is much harder and it requires either superuser access or your user account must be compromised.

b.bum


Attachment: smime.p7s
Description: S/MIME cryptographic signature

 _______________________________________________
Do not post admin requests to the list. They will be ignored.
Xcode-users mailing list      (email@hidden)
Help/Unsubscribe/Update your Subscription:

This email sent to email@hidden

  • Follow-Ups:
    • Re: Xcode 3.1 is available at connect.apple.com (Part 2b)
      • From: Jeff Johnson <email@hidden>
References: 
 >Xcode 3.1 is available at connect.apple.com (Part 2b) (From: Chris Espinosa <email@hidden>)
 >Re: Xcode 3.1 is available at connect.apple.com (Part 2b) (From: Jeff Johnson <email@hidden>)
 >Re: Xcode 3.1 is available at connect.apple.com (Part 2b) (From: Chris Espinosa <email@hidden>)
 >Re: Xcode 3.1 is available at connect.apple.com (Part 2b) (From: Jeff Johnson <email@hidden>)

  • Prev by Date: Re: Xcode 3.1 is available at connect.apple.com (Part 2b)
  • Next by Date: Re: C++ debug problem with gcc 4.2 installed by Xcode 3.1
  • Previous by thread: Re: Xcode 3.1 is available at connect.apple.com (Part 2b)
  • Next by thread: Re: Xcode 3.1 is available at connect.apple.com (Part 2b)
  • Index(es):
    • Date
    • Thread