First published: Thu Feb 02 2012(Updated: )
Apple Type Services (ATS) in Apple Mac OS X before 10.7.3 does not properly manage memory for data-font files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted font that is accessed by Font Book.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X Server | <=10.7.2 | |
Apple Mac OS X Server | =10.7.1 | |
Apple Mac OS X Server | =10.7.0 | |
macOS Yosemite | =10.7.0 | |
macOS Yosemite | <=10.7.2 | |
macOS Yosemite | =10.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3446 has been classified as a critical vulnerability due to its potential to execute arbitrary code remotely.
To fix CVE-2011-3446, update your macOS to version 10.7.3 or later.
CVE-2011-3446 can lead to arbitrary code execution or denial of service through application crashes.
CVE-2011-3446 affects macOS versions prior to 10.7.3.
Yes, CVE-2011-3446 can be exploited by remote attackers using specially crafted font files.