CVE-2013-3949: Low severity apple ios and macos vulnerability
The posixspawn system call in the XNU kernel in Apple Mac OS X 10.8.x does not prevent use of the POSIXSPAWNDISABLEASLR and POSIXSPAWNALLOWDATAEXEC flags for setuid and setgid programs, which allows local users to bypass intended access restrictions via a wrapper program that calls the posixspawnattrsetflags function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3949?
CVE-2013-3949 is classified as a medium severity vulnerability.
How do I fix CVE-2013-3949?
To fix CVE-2013-3949, it's recommended to upgrade to a non-affected version of macOS, preferably a version later than 10.8.4.
Who is affected by CVE-2013-3949?
CVE-2013-3949 affects users running Mac OS X versions 10.8.0 to 10.8.4.
What kind of attack can exploit CVE-2013-3949?
CVE-2013-3949 can be exploited by local users through a wrapper program to bypass access restrictions.
What components of macOS are impacted by CVE-2013-3949?
CVE-2013-3949 impacts the posix_spawn system call within the XNU kernel of macOS.