CVE-2013-0978: Infoleak
The ARM prefetch abort handler in the kernel in Apple iOS before 6.1.3 and Apple TV before 5.2.1 does not ensure that it has been invoked in an abort context, which makes it easier for local users to bypass the ASLR protection mechanism via crafted code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0978?
CVE-2013-0978 has been rated as a moderate severity vulnerability due to its potential to bypass ASLR protection.
How do I fix CVE-2013-0978?
To mitigate CVE-2013-0978, update your iOS device to at least version 6.1.3 or later.
What versions of iOS are affected by CVE-2013-0978?
CVE-2013-0978 affects all versions of iOS before 6.1.3 and Apple TV versions before 5.2.1.
Who can exploit CVE-2013-0978?
Local users with access to the affected devices can exploit CVE-2013-0978 to bypass security mechanisms.
What is ASLR and how is it related to CVE-2013-0978?
Address Space Layout Randomization (ASLR) is a security feature that CVE-2013-0978 can bypass, potentially allowing unauthorized code execution.