First published: Wed Jun 10 2009(Updated: )
CoreGraphics in Apple Safari before 4.0 on Windows does not properly use arithmetic during automatic hinting of TrueType fonts, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted font data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | =3.2 | |
Apple Safari | =3.0.3 | |
Apple Safari | =3.0.1 | |
Apple Safari | =3.1.2 | |
Apple Safari | <=3.2.3 | |
Apple Safari | =3.0.2 | |
Apple Safari | =3.1 | |
Apple Safari | =3.1.1 | |
Apple Safari | =3.0 | |
Apple Safari | =3.2.2 | |
Apple Safari | =3.2.1 | |
Apple Safari | =3.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1705 is considered critical due to its potential to allow remote code execution and cause application crashes.
To fix CVE-2009-1705, update Apple Safari to version 4.0 or later on Windows.
CVE-2009-1705 affects Apple Safari versions before 4.0 on Windows.
CVE-2009-1705 is a memory corruption vulnerability due to improper handling of TrueType fonts.
If exploited, CVE-2009-1705 can lead to arbitrary code execution or a denial of service through application crashes.