CVE
- Id
- 48138
- CVE No.
- CVE-2011-0226
- Status
- Candidate
- Description
- Integer signedness error in psaux/t1decode.c in FreeType before 2.4.6, as used in CoreGraphics in Apple iOS before 4.2.9 and 4.3.x before 4.3.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Type 1 font in a PDF document, as exploited in the wild in July 2011.
- Phase
- Assigned (20101223)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
523239 | 48138 | CVE-2011-0226 | MLIST:[freetype-devel] 20110708 Re: details on iPhone exploit caused by FreeType? | View |
523240 | 48138 | CVE-2011-0226 | URL:http://lists.nongnu.org/archive/html/freetype-devel/2011-07/msg00015.html | View |
523241 | 48138 | CVE-2011-0226 | MLIST:[freetype-devel] 20110708 details on iPhone exploit caused by FreeType? | View |
523242 | 48138 | CVE-2011-0226 | URL:http://lists.nongnu.org/archive/html/freetype-devel/2011-07/msg00014.html | View |
523243 | 48138 | CVE-2011-0226 | MLIST:[freetype-devel] 20110709 Re: details on iPhone exploit caused by FreeType? | View |
523244 | 48138 | CVE-2011-0226 | URL:http://lists.nongnu.org/archive/html/freetype-devel/2011-07/msg00020.html | View |
523245 | 48138 | CVE-2011-0226 | MLIST:[freetype-devel] 20110711 Re: details on iPhone exploit caused by FreeType? | View |
523246 | 48138 | CVE-2011-0226 | URL:http://lists.nongnu.org/archive/html/freetype-devel/2011-07/msg00026.html | View |
523247 | 48138 | CVE-2011-0226 | MLIST:[freetype-devel] 20110711 Re: details on iPhone exploit caused by FreeType? | View |
523248 | 48138 | CVE-2011-0226 | URL:http://lists.nongnu.org/archive/html/freetype-devel/2011-07/msg00028.html | View |
523249 | 48138 | CVE-2011-0226 | MISC:http://www.appleinsider.com/articles/11/07/06/hackers_release_new_browser_based_ios_jailbreak_based_on_pdf_exploit.html | View |
523250 | 48138 | CVE-2011-0226 | CONFIRM:http://support.apple.com/kb/HT4802 | View |
523251 | 48138 | CVE-2011-0226 | CONFIRM:http://support.apple.com/kb/HT4803 | View |
523252 | 48138 | CVE-2011-0226 | CONFIRM:http://support.apple.com/kb/HT5002 | View |
523253 | 48138 | CVE-2011-0226 | APPLE:APPLE-SA-2011-07-15-1 | View |
523254 | 48138 | CVE-2011-0226 | URL:http://lists.apple.com/archives/security-announce/2011//Jul/msg00000.html | View |
523255 | 48138 | CVE-2011-0226 | APPLE:APPLE-SA-2011-07-15-2 | View |
523256 | 48138 | CVE-2011-0226 | URL:http://lists.apple.com/archives/security-announce/2011//Jul/msg00001.html | View |
523257 | 48138 | CVE-2011-0226 | APPLE:APPLE-SA-2011-10-12-3 | View |
523258 | 48138 | CVE-2011-0226 | URL:http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html | View |
523259 | 48138 | CVE-2011-0226 | DEBIAN:DSA-2294 | View |
523260 | 48138 | CVE-2011-0226 | URL:http://www.debian.org/security/2011/dsa-2294 | View |
523261 | 48138 | CVE-2011-0226 | MANDRIVA:MDVSA-2011:120 | View |
523262 | 48138 | CVE-2011-0226 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2011:120 | View |
523263 | 48138 | CVE-2011-0226 | REDHAT:RHSA-2011:1085 | View |
523264 | 48138 | CVE-2011-0226 | URL:http://www.redhat.com/support/errata/RHSA-2011-1085.html | View |
523265 | 48138 | CVE-2011-0226 | SUSE:SUSE-SU-2011:0853 | View |
523266 | 48138 | CVE-2011-0226 | URL:http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00016.html | View |
523267 | 48138 | CVE-2011-0226 | SUSE:openSUSE-SU-2011:0852 | View |
523268 | 48138 | CVE-2011-0226 | URL:http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00015.html | View |
523269 | 48138 | CVE-2011-0226 | BID:48619 | View |
523270 | 48138 | CVE-2011-0226 | URL:http://www.securityfocus.com/bid/48619 | View |
523271 | 48138 | CVE-2011-0226 | SECUNIA:45167 | View |
523272 | 48138 | CVE-2011-0226 | URL:http://secunia.com/advisories/45167 | View |
523273 | 48138 | CVE-2011-0226 | SECUNIA:45224 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
32236 | JVNDB-2011-002476 | Apple Mac OS X の CFNetwork におけるユーザを追跡可能な脆弱性 | Apple Mac OS X の CFNetwork は、Cookie Storage ポリシーを適切に処理しないため、ユーザを追跡可能な脆弱性が存在します。 | CVE-2011-0231 | 48138 | 5 | http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002476.html | View |