Apple iOS 4.0.2 fixes security vulnerabilities

Apple released the iOS 4.0.2 Update for iPhone and iPod touch which addresses security vulnerabilities that have been making the news lately. iOS 4.0.2 can be downloaded and installed using iTunes.

The update is available for iOS 2.0 through 4.0.1 for iPhone 3G and later, iOS 2.1 through 4.0 for iPod touch (2nd generation) and later.

FreeType

A stack buffer overflow exists in FreeType’s handling of CFF opcodes. Viewing a PDF document with maliciously crafted embedded fonts may allow arbitrary code execution. This issue is addressed through improved bounds checking.

IOSurface

An integer overflow exists in the handling of IOSurface properties, which may allow malicious code running as the user to gain system privileges. This issue is addressed through improved bounds checking.