Get a Pentest and security assessment of your IT network.

Advisories

Zero Day Initiative Advisory 10-076

Zero Day Initiative Advisory 10-076 – This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple Preview. User interaction is required in that a target must open a malicious file or visit a malicious page. The specific flaw exists within the routine TType1ParsingContext::SpecialEncoding() defined in libFontParser.dylib. While parsing glyphs from a PDF document, a malformed offset greater than 0x400 can result in a heap corruption which can be leveraged by an attacker to execute arbitrary code under the context of the current user.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/88454/ZDI-10-076.txt

Source: https://packetstormsecurity.com/files/88454/Zero-Day-Initiative-Advisory-10-076.html

Related posts
Advisories

57657.html

Advisories

Secunia Security Advisory 17317

Advisories

Ubuntu Security Notice 284-1

Advisories

Hardened-PHP Project Security Advisory 2006-14.139