Apple hat soeben die iOS Verion 4.3.4 veröffentlicht. Dieses Update schließt ausschließlich die Sicherheitslücke(n) welche von JailbreakMe verwendet wird / werden. Jailbreaker sollten die Finger von dieser Firmware lassen, da der Jailbreak entfernt wird und JailbreakMe nicht mehr nutzbar ist. Stattdessen solltet ihr das kotsenlose Tool “PDF Patcher 2″ aus Cydia laden und installieren. Allen anderen sollten das Update möglichst schnell installieren, da es eine Sicherheitslücke schließt, die auch von bösartigen Schädlingen verwendet werden kann.
Direct Links:
Changelog (Apple Support):
CoreGraphicsAvailable for: iOS 3.0 through 4.3.3 for iPhone 3GS and iPhone 4 (GSM model), iOS 3.1 through 4.3.3 for iPod touch (3rd generation) and later, iOS 3.2 through 4.3.3 for iPadImpact: Viewing a maliciously crafted PDF file may lead to an unexpected application termination or arbitrary code executionDescription: A buffer overflow exists in FreeType’s handling of TrueType fonts. Viewing a maliciously crafted PDF file may lead to an unexpected application termination or arbitrary code execution.
CVE-ID
CVE-2010-3855
- CoreGraphicsAvailable for: iOS 3.0 through 4.3.3 for iPhone 3GS and iPhone 4 (GSM model), iOS 3.1 through 4.3.3 for iPod touch (3rd generation) and later, iOS 3.2 through 4.3.3 for iPadImpact: Viewing a maliciously crafted PDF file may lead to an unexpected application termination or arbitrary code execution
Description: A signedness issue exists in FreeType’s handling of Type 1 fonts. Viewing a maliciously crafted PDF file may lead to an unexpected application termination or arbitrary code execution.
CVE-ID
CVE-2011-0226
- IOMobileFrameBufferAvailable for: iOS 3.0 through 4.3.3 for iPhone 3GS and iPhone 4 (GSM model), iOS 3.1 through 4.3.3 for iPod touch (3rd generation) and later, iOS 3.2 through 4.3.3 for iPadImpact: Malicious code running as the user may gain system privileges
Description: An invalid type conversion issue exists in the use of IOMobileFrameBuffer queueing primitives, which may allow malicious code running as the user to gain system privileges.
CVE-ID
CVE-2011-0227


One Response
Trackbacks/Pingbacks
Leave a Reply