CVE-2011-1417: Integer Overflow
Integer overflow in QuickLook, as used in Apple Mac OS X before 10.6.7 and MobileSafari in Apple iOS before 4.2.7 and 4.3.x before 4.3.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a Microsoft Office document with a crafted size field in the OfficeArtMetafileHeader, related to OfficeArtBlip, as demonstrated on the iPhone by Charlie Miller and Dion Blazakis during a Pwn2Own competition at CanSecWest 2011.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1417?
CVE-2011-1417 has a high severity rating due to its potential for remote code execution and denial of service.
How do I fix CVE-2011-1417?
To fix CVE-2011-1417, users should update to the latest version of Apple Mac OS X and iOS that includes the security patch.
Which Apple products are affected by CVE-2011-1417?
CVE-2011-1417 affects Apple Mac OS X versions before 10.6.7 and iOS versions before 4.2.7.
What type of attack can exploit CVE-2011-1417?
CVE-2011-1417 can be exploited through crafted Microsoft Office documents leading to arbitrary code execution.
Is there any workaround for CVE-2011-1417?
There are no recommended workarounds for CVE-2011-1417 other than applying the security updates provided by Apple.