iOS 4.0.2 firmware update released to fix security vulnerability associated with viewing malicious PDF files

iOS 4.0.2 firmware update released to fix security vulnerability associated with viewing malicious PDF files
Apple has released iOS 4.0.2 software update. It's available for: iOS 2.0 through 4.0.1 for iPhone 3G and later, iOS 2.1 through 4.0 for iPod touch (2nd generation) and later.

FreeType CVE-ID: CVE-2010-1797
-Impact: Viewing a PDF document with maliciously crafted embedded fonts may allow arbitrary code execution
-Description: A stack buffer overflow exists in FreeType's handling of CFF opcodes. Viewing a PDF document with maliciously crafted embedded fonts may allow arbitrary code execution. This issue is addressed through improved bounds checking.

IOSurface CVE-ID: CVE-2010-2973
-Impact: Malicious code running as the user may gain system privileges
-Description: An integer overflow exists in the handling of IOSurface properties, which may allow malicious code running as the user to gain system privileges. This issue is addressed through improved bounds checking.

iOS 4.0.2 firmware update is available via iTunes.
Share :

0 comments on "iOS 4.0.2 firmware update released to fix security vulnerability associated with viewing malicious PDF files"

Post a Comment