Apple Releases Security Update 2010-003 for Leopard & Snow Leopard

Apple released Security Update 2010-003 for Leopard & Snow Leopard Wednesday, an update that addresses an issue that could allow the bad guys to take over your Mac.

Apple’s security note for the update:

Available for: Mac OS X v10.5.8, Mac OS X Server v10.5.8, Mac OS X v10.6.3, Mac OS X Server v10.6.3

Impact: Viewing or downloading a document containing a maliciously crafted embedded font may lead to arbitrary code execution.

Description: An unchecked index issue exists in Apple Type Services’ handling of embedded fonts. Viewing or downloading a document containing a maliciously crafted embedded font may lead to arbitrary code execution. This issue is addressed through improved index checking. Credit to Charlie Miller working with TippingPoint’s Zero Day Initiative for reporting this issue.

The update is available through Software Update as a 6.5MB download.