FreeType Compact Font Format (CFF) Multiple Stack Based Buffer Overflow Vulnerabilities

Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.

The Type2 'CharStrings' buffer-overflow vulnerability is being exploited to jailbreak vulnerable Apple devices.

The JailbreakMe source code was released by comex. Please see the references for details.

The following exploit code is available:


 

Privacy Statement
Copyright 2010, SecurityFocus