OSVDB ID: 35146

Title: Apple Mac OS X CoreGraphics PDF File Handling Overflow

Info

Disclosure

May 25, 2007

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

An integer overflow exists in Mac OS X. The CoreGraphics library fails to validate PDF files resulting in an integer overflow. With a specially crafted file, a context-dependent attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Local Access Required, Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Unknown
Disclosure: OSVDB Verified

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Apple has released a patch to address this vulnerability.

Products

Apple Computer, Inc.

Mac OS X

10.4
10.4.1
10.4.2
10.4.3
10.4.4
10.4.5
10.4.6
10.4.7
10.4.8
10.4.9

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/35146