CERT-In Vulnerability Note
CIVN-2010-0227
Microsoft Windows Embedded OpenType Font Engine Integer Overflow Vulnerability
Original Issue Date:October 15, 2010
Severity Rating: HIGH
Systems Affected
- Windows XP SP3 and prior
- Windows XP Service Pack 3
- Windows XP Professional x64 Edition Service Pack 2
- Windows Server 2003 Service Pack 2
- Windows Server 2003 x64 Edition Service Pack 2
- Windows Server 2003 with SP2 for Itanium-based Systems
- Windows Vista Service Pack 1 and Windows Vista Service Pack 2
- Windows Vista x64 Edition Service Pack 1 and Windows Vista x64 Edition Service Pack 2
- Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2008 for x64-based Systems and Windows Server 2008 for x64-based Systems Service Pack 2
- Windows Server 2008 for Itanium-based Systems and Windows Server 2008 for Itanium-based Systems Service Pack 2
- Windows 7 for 32-bit Systems
- Windows 7 for x64-based Systems
- Windows Server 2008 R2 for x64-based Systems
- Windows Server 2008 R2 for Itanium-based Systems
Overview
A integer overflow vulnerability has been reported in Windows Embedded OpenType Font Engine that could allow an remote unauthenticated attacker to execute arbitrary code.
Description
Embedded OpenType (EOT) fonts are a compact form of fonts designed for use on web pages. A integer overflow vulnerability exists in the way Microsoft Windows Embedded OpenType (EOT) font engine parses hdmx records in specially crafted embedded fonts. This vulnerability exists due to error in parsing code of MTX_TTC_CTF_To_TTF function within t2embed.dll .
A remote attacker can exploit this vulnerability via a specially crafted EOT file. An attacker who successfully exploited this vulnerability could execute arbitrary code on a vulnerable system.
Solution
Apply patches as mentioned in Microsoft Security bulletin
MS10-076
Vendor Information
Microsoft
http://www.microsoft.com/technet/security/Bulletin/MS10-076.mspx
References
Microsoft
http://www.microsoft.com/technet/security/Bulletin/MS10-076.mspx
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=21470
Security Tracker
http://securitytracker.com/alerts/2010/Oct/1024544.html
CVE Name
CVE-2010-1883
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|