CVE-2013-3952: Low severity apple ios and macos vulnerability
Published Jun 5, 2013
·Updated
The fillpipeinfo function in bsd/kern/syspipe.c in the XNU kernel in Apple Mac OS X 10.8.x allows local users to defeat the KASLR protection mechanism via the PROCPIDFDPIPEINFO option to the procinfo system call for a kernel pipe handle.
Affected Software
5 affected components
Apple iOS and macOS=10.8.0
Apple iOS and macOS=10.8.1
Apple iOS and macOS=10.8.2
Apple iOS and macOS=10.8.3
Apple iOS and macOS=10.8.4
Event History
Jun 5, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3952?
CVE-2013-3952 is considered a medium severity vulnerability due to its potential impact on the KASLR protection mechanism.
2
How do I fix CVE-2013-3952?
To fix CVE-2013-3952, update your Apple Mac OS X to a version after 10.8.4 that resolves this vulnerability.
3
Who is affected by CVE-2013-3952?
CVE-2013-3952 affects local users on Apple Mac OS X versions 10.8.0 to 10.8.4.
4
What does CVE-2013-3952 exploit?
CVE-2013-3952 exploits the PROC_PIDFDPIPEINFO option in the proc_info system call related to kernel pipe handles.
5
What version of macOS contains CVE-2013-3952?
CVE-2013-3952 is present in Apple Mac OS X versions 10.8.0 to 10.8.4.