Zero Day Initiative Advisory 09-023 – This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple OS X. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw appears to exist in the ATSServer font server upon parsing of malicious Compact Font Format files. A boundary condition exists in the parsing of internal dictionaries that can lead to a memory corruption allowing the execution of arbitrary code.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/77671/ZDI-09-023.txt
Source: https://packetstormsecurity.com/files/77671/Zero-Day-Initiative-Advisory-09-023.html

