Peaches Posted July 15, 2009 Report Share Posted July 15, 2009 Windows Embedded OpenType Font Engine Two VulnerabilitiesHIGHLY CRITICALTwo vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system.1) A boundary error in the Embedded OpenType (EOT) Font Engine component when parsing data records in embedded fonts can be exploited to cause a heap-based buffer overflow via a specially crafted embedded font.2) An integer overflow error in the Embedded OpenType (EOT) Font Engine component when parsing name tables in embedded fonts can be exploited to corrupt memory via a specially crafted embedded font.Successful exploitation of the vulnerabilities allows execution of arbitrary code when a user e.g. visits a malicious web page.secunia advisories - http://secunia.com/advisories/35773/ Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.