6.2
CVSSv2

CVE-2013-3955

Published: 05/06/2013 Updated: 11/10/2013
CVSS v2 Base Score: 6.2 | Impact Score: 10 | Exploitability Score: 1.9
VMScore: 552
Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

The get_xattrinfo function in the XNU kernel in Apple iOS 5.x and 6.x up to and including 6.1.3 on iPad devices does not properly validate the header of an AppleDouble file, which might allow local users to cause a denial of service (memory corruption) or have unspecified other impact via an invalid file on an msdosfs filesystem.

Vulnerable Product Search on Vulmon Subscribe to Product

apple iphone_os 5.0

apple iphone_os 6.0

apple iphone_os 6.1

apple iphone_os 5.0.1

apple iphone_os 5.1

apple iphone_os 6.0.1

apple iphone_os 6.1.3

apple iphone_os 6.0.2

apple iphone_os 5.1.1

apple iphone_os 6.1.2

apple ipad

apple ipad_mini -

apple ipad2 -