Skip to main content

Apple Mac OS X ATSServer CFF Font Parsing Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 10 Nov 2010 4972 Views

RISK: Medium Risk

A vulnerability has been identified in Apple Mac OS X, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a memory corruption error in the Apple Type Services (ATS) when processing embedded CFF fonts, which could allow attackers to execute arbitrary code by tricking a user into opening a specially crafted document (e.g. PDF).


Impact

  • Remote Code Execution

System / Technologies affected

  • Apple Mac OS X versions 10.5.x
  • Apple Mac OS X Server versions 10.5.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Upgrade to Apple Mac OS X versions 10.6.


Vulnerability Identifier

  • No CVE information is available

Source


Related Link