code is just a tactic
Showing 1 - 1 of 1 RSS Feed

Files

iDEFENSE Security Advisory 2008-07-31.1
Posted Aug 1, 2008
Authored by iDefense Labs, Pariente Kobi | Site idefense.com

iDefense Security Advisory 07.31.08 - Remote exploitation of an integer overflow vulnerability in Apple Inc.'s Mac OS X could allow an attacker to execute arbitrary code with the privileges of the currently logged in user. This vulnerability exists due to the way PDF files containing Type 1 fonts are handled. When processing a font with an overly large length, integer overflow could occur. This issue leads to heap corruption which can allow for arbitrary code execution. iDefense has confirmed the existence of this vulnerability in Mac OS X version 10.5.2. Previous versions may also be affected.

tags | advisory, remote, overflow, arbitrary, code execution
systems | apple, osx
advisories | CVE-2008-2322
MD5 | 772937f408af6494ec81f8661b04c5fb
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close