LOW
The ARM prefetch abort handler in the kernel in Apple iOS before 6.1.3 and Apple TV before 5.2.1 does not ensure that it has been invoked in an abort context, which makes it easier for local users to bypass the ASLR protection mechanism via crafted code
Published Mar 20, 2013
2.1
LOWCVSS 2.0
EPSS 0.35%
Description
The ARM prefetch abort handler in the kernel in Apple iOS before 6.1.3 and Apple TV before 5.2.1 does not ensure that it has been invoked in an abort context, which makes it easier for local users to bypass the ASLR protection mechanism via crafted code.
Affected products
No data.
Configuration 1
OR
- ≤ 6.1.2
- 1.0.0
- 1.0.1
- 1.0.2
- 1.1.0
- 1.1.0
- 1.1.1
- 1.1.2
- 1.1.2
- 1.1.3
- 1.1.3
- 1.1.4
- 1.1.4
- 1.1.5
- 1.1.5
- 2.0
- 2.0.0
- 2.0.0
- 2.0.1
- 2.0.1
- 2.0.2
- 2.0.2
- 2.1
- 2.1
- 2.1.1
- 2.2
- 2.2
- 2.2.1
- 2.2.1
- 3.0
- 3.0
- 3.0.1
- 3.0.1
- 3.1
- 3.1
- 3.1.2
- 3.1.2
- 3.1.3
- 3.1.3
- 3.2
- 3.2
- 3.2.1
- 3.2.1
- 3.2.2
- 4.0
- 4.0
- 4.0.1
- 4.0.1
- 4.0.2
- 4.1
- 4.2.1
- 4.2.5
- 4.2.8
- 4.3.0
- 4.3.1
- 4.3.2
- 4.3.3
- 4.3.5
- 4.3.5
- 4.3.5
- 5.0
- 5.0
- 5.0
- 5.0.1
- 5.0.1
- 5.0.1
- 5.1
- 5.1.1
- 6.0
- 6.0.1
- 6.0.2
- 6.1
Configuration 2
OR
- ≤ 5.2.0
- 1.0.0
- 1.1.0
- 2.0.0
- 2.0.1
- 2.0.2
- 2.1.0
- 2.2.0
- 2.3.0
- 2.3.1
- 2.4.0
- 3.0.0
- 3.0.1
- 3.0.2
- 4.1.0
- 4.1.1
- 4.2.0
- 4.2.1
- 4.2.2
- 4.3.0
- 4.4.0
- 4.4.2
- 4.4.3
- 4.4.4
- 5.0.0
- 5.0.1
- 5.0.2
- 5.1.0
- 5.1.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://lists.apple.com/archives/security-announce/2013/Mar/msg00004.html vendor-advisoryx_refsource_APPLEVendor Advisory
- http://lists.apple.com/archives/security-announce/2013/Mar/msg00005.html vendor-advisoryx_refsource_APPLEVendor Advisory
- http://support.apple.com/kb/HT5702 x_refsource_CONFIRMVendor Advisory
- http://support.apple.com/kb/HT5704 x_refsource_CONFIRMVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-0989 Advisory
| Link | Providers | Tags |
|---|---|---|
| http://lists.apple.com/archives/security-announce/2013/Mar/msg00004.html | vendor-advisoryx_refsource_APPLEVendor Advisory | |
| http://lists.apple.com/archives/security-announce/2013/Mar/msg00005.html | vendor-advisoryx_refsource_APPLEVendor Advisory | |
| http://support.apple.com/kb/HT5702 | x_refsource_CONFIRMVendor Advisory | |
| http://support.apple.com/kb/HT5704 | x_refsource_CONFIRMVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-0989 | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apple
Published Mar 20, 2013
Updated Sep 17, 2024
Reserved Jan 10, 2013
Link CVE-2013-0978
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2013-0989 Assigner apple
Published Mar 20, 2013
Updated Sep 17, 2024
Exploited since n/a
Link EUVD-2013-0989