[] NeoSense

Acrobat Acrobat - Font Parsing Integer Overflow

Author: Ramz Afzar
type: dos
platform: windows
port: 
date_added: 2010-08-14 
date_updated: 2010-08-14 
verified: 1 
codes: CVE-2010-2862;OSVDB-66859 
tags: 
aliases: VA010-003.tgz 
screenshot_url:  
application_url: 

From the authors site:

In this article, I'm going to share with you my observations and analysis on recent Adobe Acrobat Font Parsing vulnerability. Source document exists here:

http://securityevaluators.com/files/papers/CrashAnalysis.pdf (page 51-58)

After reading the paper, I started studying the TTF format. After initial research, I wrote this script:

Writeup and proof of concept files included in archive file.

https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/14642.tgz (VA010-003.tgz)