|
|
|
![]() |
Vulnerability Note VU#172948Apple Mac OS X AppKit vulnerable to buffer overflow via maliciously crafted Microsoft Word filesOverviewA buffer overflow vulnerability exists in a component of Apple's Mac OS X operating system that handles Microsoft Word files.I. DescriptionThe Cocoa Application Framework (also referred to as the Application Kit, or AppKit) is one of the core Cocoa frameworks supplied with Apple's Mac OS X operating system. It provides functionality and associated Application Program Interfaces (APIs) for applications, including objects for graphical user interfaces (GUIs), event-handling mechanisms, application services, and drawing and image composition facilities.A buffer overflow exists in the AppKit component designed to handle Microsoft Word (.doc) files. Apple notes in its security advisory that this vulnerability only affects applications that use AppKit (such as TextEdit) and that Microsoft Word for Mac OS X is not vulnerable. A maliciously crafted .doc file could be used to execute arbitrary code on a vulnerable system.
References
Thanks to Apple Product Security for reporting this vulnerability. This document was written by Chad Dougherty based on information supplied by Apple.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||