First published: Wed Jun 05 2013(Updated: )
The fill_pipeinfo function in bsd/kern/sys_pipe.c in the XNU kernel in Apple Mac OS X 10.8.x allows local users to defeat the KASLR protection mechanism via the PROC_PIDFDPIPEINFO option to the proc_info system call for a kernel pipe handle.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | =10.8.0 | |
macOS Yosemite | =10.8.1 | |
macOS Yosemite | =10.8.2 | |
macOS Yosemite | =10.8.3 | |
macOS Yosemite | =10.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3952 is considered a medium severity vulnerability due to its potential impact on the KASLR protection mechanism.
To fix CVE-2013-3952, update your Apple Mac OS X to a version after 10.8.4 that resolves this vulnerability.
CVE-2013-3952 affects local users on Apple Mac OS X versions 10.8.0 to 10.8.4.
CVE-2013-3952 exploits the PROC_PIDFDPIPEINFO option in the proc_info system call related to kernel pipe handles.
CVE-2013-3952 is present in Apple Mac OS X versions 10.8.0 to 10.8.4.