CVE-2011-3446: High severity Apple Mac OS X Server vulnerability
Published Feb 2, 2012
·Updated
Apple Type Services (ATS) in Apple Mac OS X before 10.7.3 does not properly manage memory for data-font files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted font that is accessed by Font Book.
Affected Software
6 affected components
Apple Mac OS X Server<=10.7.2
Apple Mac OS X Server=10.7.1
Apple Mac OS X Server=10.7.0
Apple iOS and macOS=10.7.0
Apple iOS and macOS<=10.7.2
Apple iOS and macOS=10.7.1
Event History
Feb 2, 2012
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-3446?
CVE-2011-3446 has been classified as a critical vulnerability due to its potential to execute arbitrary code remotely.
2
How do I fix CVE-2011-3446?
To fix CVE-2011-3446, update your macOS to version 10.7.3 or later.
3
What are the potential impacts of CVE-2011-3446?
CVE-2011-3446 can lead to arbitrary code execution or denial of service through application crashes.
4
Which versions of macOS are affected by CVE-2011-3446?
CVE-2011-3446 affects macOS versions prior to 10.7.3.
5
Can CVE-2011-3446 be exploited by remote attackers?
Yes, CVE-2011-3446 can be exploited by remote attackers using specially crafted font files.