MAAS History
Archives
« Apple Updates Server Admin Tool 10.6.3 | Main | Adobe Releases Critical Security Update »
Wednesday
Apr142010

APPLE-SA-2010-04-14-1 Security Update 2010-003  

Apple has released a security update for Mac OSX 10.6.x client/server and an update for Mac OSX 10.5.x  client/server to address the unchecked issue in Apple Type Services (ATS) discovered by Charlie Miller. Due to uncheck indexing within ATS maliciously crafted embedded fonts will result in application failure and arbitrary code execution. ATS is a legacy framework, currently CoreText is used for Unicode. ATS is prone to various memory-corruption issues as well and is used across various applications so users need to perform this update, Apple recommends developers use Core Text and Core Graphics. It is safe to say that based on the information provided that someone with malicious intent can produce this exploit.

http://developer.apple.com/mac/library/documentation/Carbon/Conceptual/Carbon64BitGuide/OtherAPIChanges/OtherAPIChanges.html

http://support.apple.com/downloads/

PrintView Printer Friendly Version

EmailEmail Article to Friend

References (2)

References allow you to track sources for this article, as well as articles that were written in response to this article.

Reader Comments

There are no comments for this journal entry. To create a new comment, use the form below.
Member Account Required
You must have a member account on this website in order to post comments. Log in to your account to enable posting.