T1 Font Integer Overflow

From The iPhone Wiki
Revision as of 03:13, 7 July 2011 by Beej (talk | contribs) (Description: Conjugate point correctly)
Jump to: navigation, search

The T1 Font Integer Overflow is a vulnerability used in Saffron. It is very similar to the Malformed CFF Vulnerability, hence why comex named its exploitation "DejaVu."[1]

Credit for Exploitation

comex

Description

When dealing with op_callothersubr, arg_cnt is defined as an integer. arg_cnt is read from decoder->stack, which could be set to 0xfea50000 by charstring "fb ef". And this will bypass stack checking. Then "top -= arg_cnt" will make top point to data outside of decoder->stack. Actually it points to decoder->parse_callback.

This vulnerability was actually addressed by Apple in Mac OS X v10.6.8/Security Update 2011-004, but a fix was never pushed to iOS. Its CVE identifier is CVE-2011-0202.

Sources