ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Apple to patch JailbreakMe.com flaw this week

By | August 9, 2010, 11:22am PDT

Summary: Barring last minute hiccups, Apple will ship a critical iOS patch this week to fix the vulnerabilities exploited by the JailbreakMe.com site.

Barring last minute hiccups, Apple will ship a critical iOS patch this week to fix the vulnerabilities exploited by the JailbreakMe.com site.

The patch will be distributed via Apple’s software update mechanism and will be available for iPhone, iPad and iPod Touch devices.

The exploit, which combines a bug in the way Apple’s mobile operating system processes CFF fonts with a privilege escalation vulnerability to escape the sandbox, allows the automated jailbreaking of iPhone/iPad/iPod Touch devices from a specially created Web site.

As the image above shows, a device simply needs to use MobileSafari to surf to a Web site, then push the slider to the right to begin the jailbreaking/expoitation process.

Now that the information on the security hole is publicly available, there is a strong likelihood of malicious copycat attacks.

Here’s the skinny on the CFF font vulnerability, via the U.S. Computer Emergency Response Team:

follow Ryan Naraine on twitter

FreeType is a font engine that can open and process font files. FreeType 2 includes the ability to handle a number of font types, including Compact Font Format (CFF). FreeType is used by a number of applications, including PDF readers, web browsers, and other applications. FreeType 2 contains a flaw in the handling of some CFF opcodes, which can result in stack corruption. This can allow arbitrary code execution.

By causing an application that uses FreeType to parse a specially-crafted CFF font, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. This can occur as the result of opening a PDF document or viewing a web page.

Apple’s security team has been scrambling to figure out the issue and come up with a fix and I’m told the patch is on schedule for release this week.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues.

Disclosure

Ryan Naraine

The most important disclosure is of my employment with Kaspersky Lab as a member of the global research and analysis team. Kaspersky Lab is a global company specializing in anti-malware and secure content management technologies. I do not own stocks or other investments in any technology company.

Biography

Ryan Naraine

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the globe. He is taking a leadership role in developing the company's online community initiative around secure content management technologies.

Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.

Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?
22
Comments

Join the conversation!

0 Votes
+ -
So typical
no_axe_to__grind 9th Aug 2010
The reality of Apple is shining through. Easy to break into, easy to exploit. All the fanbois that ***** about Windows can now go into hiding and, hopefully, stay there.
@no_axe_to__grind - "Easy to break into??" - for undoubtedly most popular Smartphone in the world (and one of the biggest targets) I'd say that iOS has been fairly resilient to date. The previous malware exploits against the iPhone effected JailBroken phones. Check your facts if you want people to take you seriously ? posted from a non-fanbois (who owns an iPhone, Androids & WinMo -- but NO BBs any longer...)
0 Votes
+ -
RE: Apple to patch JailbreakMe.com flaw this week
Pete "athynz" Athens 9th Aug 2010
@no_axe_to__grind Not that easy really - this requires user interaction... the whole "push the slider to the right" thing. Right now AFAIK one cannot just go to a website with the iPhone Safari browser and be subject to any sort of exploit like this without doing something like clicking a link on that site or other interaction. And I really should go without saying that people should stay away from sketchy-seeming sites on their mobile devices just as they would a desktop or laptop.
0 Votes
+ -
@athynz Regardless of what your OS is, if you are clicking 'OK' or in this case sliding a slider because you were prompted to by some unknown web site, you are in trouble. My question is why Microsoft get's ruthlessly criticized for this while on an Apple product it's just those dumb users fault?
0 Votes
+ -
@athynz it needs no user interaction. The website is just desigbed that way for courtesy purposes. They could auto jail break the phone if they really wanted to
0 Votes
+ -
the slider is a courtesy
erik.soderquist 10th Aug 2010
@athynz

the exploit does not require user interaction, the JailbreakMe.com site has the slider as a courtesty to its users.
0 Votes
+ -
@no_axe_to__grind and Windows ISN'T easy to break into? All those security updates are just busy work for the coders in Redmond?
I'm starting to see who the fanboi is here.
www.dfwsupergeek.com
0 Votes
+ -
@unclefixer@... its actually a lot harder to exploit windows these days than u might think. It would require user interaction aswell in most cases. It's just that 99% of hackers on the planet are trying to hack Windows where only 1% are working on everything else.
0 Votes
+ -
@ Jimster480

The giveaway in your statement is:
its actually a lot harder to exploit windows these days than u might think

By these days, you mean compared to the past?

By than you might think, you mean it is not as easy as you expect from the past?

It's just that 99% of hackers on the planet are trying to hack Windows where only 1% are working on everything else.

And as we know trying to hack into 64% of mobile internet users is just not worth anyone's time is it now?

Or in my country to hack into 21% of all mobile phone user's devices - who cares about such a small market share as that???

Clearly nobody wants to steal from mobile users who have iPhones - they wouldn't have any money in their accounts when they use their mobile banking app - which all major banks here have for the iPhone.

And only 21% of all mobile users in a country where mobile use is outstripping landline use - not worth it really!!!

/sarcasm

Where do you people get off spouting such rubbish?
0 Votes
+ -
Apple ... Adobe
MDev@... 9th Aug 2010
Gee -- Apple's having trouble with an Adobe font format. And I thought those guys got along so well...
0 Votes
+ -
@MDev@...
Not only Adobe... These are malicious Microsoft bytes that are sent to iPhone shocked
Sounds like "...every smartphone has antenna problem". Now it is adobes fault happy
0 Votes
+ -
@pauliusp

The antenna 'problem' that my Sony-Ericsson also has - as does everyone else?

Are you bashing Sony-Ericsson for selling phones that are blocked by the user holding them? If not, why not?

Now it's your fault for speaking without any real truth. happy
@MDev@... like, oh, flash for example; the Linux and Mac crowds harp on the fact that Microsoft should have built their OS such that this would not be possible. This argument has a certain validity.

That said, why should we let Apple off the hook? Why is it that flash (and other third party application problems) on Windows are Microsoft's fault while when it happens on an Apple product, it's the third party software that is to blame. You can't have it both ways.
0 Votes
+ -
@cornpie

What third party software - who said that?

Apple dropped Adobe reader - very sensibly.

And Adobe reader had similar issues a short time ago - so no, they would not have been better off with Adobe.
Kind of expected.
I'm curious how many folks now jb will actually install the update...
How long till jb is again available...
Nice how they fix this but the prox sensor and other issues are backseat...

popcorn...
0 Votes
+ -
@zenwalker

Fixing a security hole is a higher priority than fixing a sensor don't you think?

Would you rather have your phone hacked, or the screen blanking at the wrong time?

Which would you rather have fixed if you were actually speaking as a user rather than a spin merchant out to kill a product?
0 Votes
+ -
LOL - I thought this was a feature, not a bug. All goose-step to Jobs...
0 Votes
+ -
@Lonestar2

How long did it take to get Hitler into this debate - look that up?

Misinformation campaign member Lonestar 2 - you have won the prize!!!
0 Votes
+ -
@richardw66

I accept...BTW, do you wear a brown shirt?

All kidding aside, Apple has always been fanatical about the proprietary nature of their products both hardware and software. If you don't follow Apple's policies to the letter you are ostracized with voided warranties or code releases that break what, in my opinion in many cases, you should be able to do with a product you own.

So I stand by my analogy. You are free to love or hate Apple as you wish...I have no patents on that wink
0 Votes
+ -
For those who have problem downloading jailbreakme. I have been trying this on my iphone 3g with os4. finally I downloaded os4.0.1 and it worked. Some of us may have a beta version of OS 4 that has a conflict . hope this helps
0 Votes
+ -
For those having trouble with the download . I have an iphone 3g with OS 4 . For a week I tried to download to no avail. Finally I upgraded to OS 4.0.1 and the download worked. I think some of us had a beta version which conflicted Hope this helps

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix