IntoMobile

Breaking news, information, and analysis on the latest mobile phones and mobile technology

Open NavigationOpen Search
  • Home
  • Platforms
    • iOS / iPhone OS
    • Android
    • Windows Phone
    • BlackBerry OS
  • Hardware
    • New Hardware
    • Tablets
    • Reviews
    • Rumors
  • Carriers
    • AT&T
    • Sprint
    • T-Mobile
    • Verizon
  • Manufacturers
    • Apple
    • Samsung
    • HTC
    • LG
    • Motorola
  • Best VPNs
    • Best VPNs for iPhone
    • Best VPNs for Android

iOS 4.3.4 update fixes iPhone, iPad PDF security flaw

July 18, 2011 by Marc Flores - 4 Comments

Share on Twitter Share on Facebook ( 0 shares )

Apple said two weeks ago that it was aware of an iOS security flaw that could leave iPhone and iPad users vulnerable to attack via malicious PDF files. The exploit could have been used by hackers to gain access to Apple mobile devices and view user data, or infect the devices without user knowledge. Apple promised an update to patch the flaw, and it’s available now through iTunes.

Software version 4.3.4 promises to fix the critical security issues, along with other minor bug fixes. According to Apple’s security update page:

Available for: iOS 3.0 through 4.3.3 for iPhone 3GS and iPhone 4 (GSM model), iOS 3.1 through 4.3.3 for iPod touch (3rd generation) and later, iOS 3.2 through 4.3.3 for iPad

Impact: Viewing a maliciously crafted PDF file may lead to an unexpected application termination or arbitrary code execution

Description: A buffer overflow exists in FreeType’s handling of TrueType fonts. Viewing a maliciously crafted PDF file may lead to an unexpected application termination or arbitrary code execution.

The update is for GSM models of the iPhone 4, iPhone 3GS, iPad 2 and third and fourth iPod touch models. For the CDMA iPhone users on Verizon, software version 4.2.9 is available.

There is also an IOMobileFrameBuffer fix:

Available for: iOS 3.0 through 4.3.3 for iPhone 3GS and iPhone 4 (GSM model), iOS 3.1 through 4.3.3 for iPod touch (3rd generation) and later, iOS 3.2 through 4.3.3 for iPad

Impact: Malicious code running as the user may gain system privileges

Description: An invalid type conversion issue exists in the use of IOMobileFrameBuffer queueing primitives, which may allow malicious code running as the user to gain system privileges.

If you own any of the aforementioned devices, and haven’t yet updated your software, it is highly recommended you do so in order to protect your device from any malicious software or attacks. Be sure you have time, however, as the file size for the software fix is close to 700MB. Depending on your connection speed, the total download and update time may take up to 25 minutes.

Share on Twitter Share on Facebook ( 0 shares )

Back to top ▴

Back to top ▴

Follow IntoMobile

38k
36k
4k
13k
12k

Most Recent Posts

  • iPhone No Sound: Tips on How to Fix this Common Issue
  • The newest iOS – things you surely did not know
  • Transferring money through mobile: Why digital wallets are the future of commerce?
  • Review: Shine laser light Bluetooth headphones
  • Neptune Suite smart watch with phone and tablet screens killing it at Indiegogo

Get Updates Via E-Mail

  • This field is for validation purposes and should be left unchanged.

About IntoMobile

  • About IntoMobile
  • Contact IntoMobile
  • Send us News Tips
  • Privacy Policy

Social Links

  • IntoMobile on Facebook
  • IntoMobile on Twitter
  • IntoMobile on Google+
  • IntoMobile on YouTube

Copyright © 2006-2021 IntoMobile. All rights reserved.