Intrusion Prevention

FreeType.CFF.Jailbreak.Apple.Device.Buffer.Overflow

Description

This indicates an attack attempt against a buffer-overflow vulnerability in FreeType Compact Font Format(CFF). CFF is supported in some popular document formats including PDF.
This vulnerability is being exploited to jailbreak vulnerable Apple devices.

Affected Products

FreeType 2.4
FreeType 2.3.6
FreeType 2.3.5
FreeType 2.3.4
FreeType 2.3.3
FreeType 2.2.10
FreeType 2.2.1
FreeType 2.2
FreeType 2.1.10
FreeType 2.1.9
FreeType 2.1.7
FreeType 2.0.9
FreeType 2.0.6

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Recommended Actions

Upgrade to the latest version, available from the following web site:
http://www.freetype.org

CVE References

CVE-2010-1797