U programskom paketu Pages u operacijskom sustavu iOS otkrivena je sigurnosna ranjivost koja se može iskoristiti za udaljeno izvođenje DoS napada i pokretanje proizvoljnog programskog koda.
Ranjivost se očituje kao cjelobrojno prepisivanje pri otvaranju Microsoft Office Word dokumenta s posebno oblikovanim poljem u OfficeArtMetafileHeader.
Posljedica:
Podmetanjem posebno oblikovane Word datoteke, udaljeni napadač može izvesti DoS napad i pokrenuti proizvoljni programski kod.
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
APPLE-SA-2011-10-12-5 Pages for iOS v1.5
Pages for iOS v1.5 is now available and addresses the following:
Pages
Available for: iOS
Impact: Opening a maliciously crafted Microsoft Word document may
lead to an unexpected application termination or arbitrary code
execution
Description: A memory corruption issue existed in the handling of
Microsoft Word documents. Opening a maliciously crafted Microsoft
Word document in Pages may lead to an unexpected application
termination or arbitrary code execution.
CVE-ID
CVE-2011-1417 : Charlie Miller and Dion Blazakis working with
TippingPoint's Zero Day Initiative
Pages for iOS v1.5 is available for download via the App Store.
To check the current version of software, select
"Settings -> Pages -> Version".
Information will also be posted to the Apple Security Updates
web site: http://support.apple.com/kb/HT1222
This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.16 (Darwin)
iQEcBAEBAgAGBQJOlcw5AAoJEGnF2JsdZQee6ToH/12zfiky7n/WeHgWmeE09SJd
cQvbeG1w0u3dd4YFay0tq9MKFZUM9gO+ENktouUS+PWPPn+C6BEQuniGx7HR+UKr
RCIUfIvsZphBb2F+GO4PjanOmZ2Yl3xXgOIcvQPVKm6T2uNc8rbcYjFsmW+57FOa
98etSMUaSF6hcX97sN19r6/5qcS9XzWHFtenPbIq9pInHxxja1mSRDM11pt6qrkz
rSLuh/bNjmZGrsF9McJe7F1n6fsqCXYaXuV+ZcfUvfZZgVhPJe2KSoP/fzNFbmuS
eWvv+4FHNIzmuapgoeglpBQy7X0vMc1R+JLqRytjZ6LPK2HifZpiZVeVW3y4r98=
=f/3c
-----END PGP SIGNATURE-----
_______________________________________________
Do not post admin requests to the list. They will be ignored.
Security-announce mailing list (Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.)
Help/Unsubscribe/Update your Subscription:
http://lists.apple.com/mailman/options/security-announce/advisory%40lss.hr
This email sent to Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
Posljednje sigurnosne preporuke