CVE-2012-3749: Infoleak
The extensions APIs in the kernel in Apple iOS before 6.0.1 provide kernel addresses in responses that contain an OSBundleMachOHeaders key, which makes it easier for remote attackers to bypass the ASLR protection mechanism via a crafted app.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3749?
CVE-2012-3749 has a medium severity rating as it can allow remote attackers to bypass the ASLR protection mechanism.
How do I fix CVE-2012-3749?
To fix CVE-2012-3749, update to iOS version 6.0.1 or later as it contains the necessary security patches.
What is the impact of exploiting CVE-2012-3749?
Exploitation of CVE-2012-3749 can potentially allow attackers to gain access to memory addresses, facilitating further attacks on the iOS device.
Which devices are affected by CVE-2012-3749?
CVE-2012-3749 affects all iOS versions before 6.0.1, impacting a wide range of Apple devices including iPhones and iPads.
Is there any workaround for CVE-2012-3749?
There are no effective workarounds for CVE-2012-3749; the recommended action is to update the operating system.