6.9
CVSSv2

CVE-2013-3954

Published: 05/06/2013 Updated: 31/10/2013
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The posix_spawn system call in the XNU kernel in Apple Mac OS X 10.8.x does not properly validate the data for file actions and port actions, which allows local users to (1) cause a denial of service (panic) via a size value that is inconsistent with a header count field, or (2) obtain sensitive information from kernel heap memory via a certain size value in conjunction with a crafted buffer.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x 10.8.2

apple mac os x 10.8.1

apple mac os x 10.8.3

apple mac os x 10.8.4

apple mac os x 10.8.0

apple iphone os 1.1.1

apple iphone os 1.1.2

apple iphone os 2.1

apple iphone os

apple iphone os 1.1.3

apple iphone os 1.1.4

apple iphone os 1.1.5

apple iphone os 2.2

apple iphone os 2.2.1

apple iphone os 3.2.1

apple iphone os 3.2.2

apple iphone os 4.2.8

apple iphone os 4.3.0

apple iphone os 4.3.1

apple iphone os 5.1.1

apple iphone os 6.0

apple iphone os 1.0.0

apple iphone os 1.0.1

apple iphone os 2.0

apple iphone os 2.0.0

apple iphone os 3.0

apple iphone os 3.0.1

apple iphone os 4.0

apple iphone os 4.0.1

apple iphone os 4.3.2

apple iphone os 4.3.3

apple iphone os 6.0.1

apple iphone os 6.0.2

apple iphone os 2.1.1

apple iphone os 3.1.3

apple iphone os 3.2

apple iphone os 4.2.1

apple iphone os 4.2.5

apple iphone os 5.0.1

apple iphone os 5.1

apple iphone os 6.1.3

apple iphone os 1.0.2

apple iphone os 1.1.0

apple iphone os 2.0.1

apple iphone os 2.0.2

apple iphone os 3.1

apple iphone os 3.1.2

apple iphone os 4.0.2

apple iphone os 4.1

apple iphone os 4.3.5

apple iphone os 5.0

apple iphone os 6.1

apple iphone os 6.1.2