Get a Pentest and security assessment of your IT network.

Advisories

Zero Day Initiative Advisory 10-076

Zero Day Initiative Advisory 10-076 – This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple Preview. User interaction is required in that a target must open a malicious file or visit a malicious page. The specific flaw exists within the routine TType1ParsingContext::SpecialEncoding() defined in libFontParser.dylib. While parsing glyphs from a PDF document, a malformed offset greater than 0x400 can result in a heap corruption which can be leveraged by an attacker to execute arbitrary code under the context of the current user.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/88454/ZDI-10-076.txt

Source: https://packetstormsecurity.com/files/88454/Zero-Day-Initiative-Advisory-10-076.html

Related posts
Advisories

LynX-adv4_SignatureDB.txt

Advisories

Secunia Security Advisory 16497

Advisories

Secunia Security Advisory 19451

Advisories

Debian Linux Security Advisory 1187-1