CVE-2013-3954: Input Validation
The posixspawn system call in the XNU kernel in Apple Mac OS X 10.8.x does not properly validate the data for file actions and port actions, which allows local users to (1) cause a denial of service (panic) via a size value that is inconsistent with a header count field, or (2) obtain sensitive information from kernel heap memory via a certain size value in conjunction with a crafted buffer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3954?
CVE-2013-3954 is classified as a medium severity vulnerability that can lead to denial of service or information disclosure.
How do I fix CVE-2013-3954?
To fix CVE-2013-3954, ensure that your system is updated to the latest version of macOS, which addresses this vulnerability.
Who is affected by CVE-2013-3954?
CVE-2013-3954 affects users of Apple macOS versions 10.8.0 through 10.8.4 and certain versions of iPhone OS.
What are the potential impacts of CVE-2013-3954?
The impact of CVE-2013-3954 includes local denial of service attacks and potential sensitive data exposure.
Is there a workaround for CVE-2013-3954?
There are no official workarounds for CVE-2013-3954, so updating to the latest version is the best course of action.