CVE-2013-5144: Null Pointer Dereference
Passcode Lock in Apple iOS before 7.0.3 on iPhone devices allows physically proximate attackers to bypass an intended passcode requirement, and dial arbitrary telephone numbers, by tapping the emergency-call button during a certain notification and camera-pane state to trigger a NULL pointer dereference.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5144?
CVE-2013-5144 is considered a high-severity vulnerability due to the potential for unauthorized access to sensitive functions on affected iPhone devices.
How do I fix CVE-2013-5144?
To fix CVE-2013-5144, users should update their iOS to version 7.0.3 or later.
Which versions of iOS are affected by CVE-2013-5144?
CVE-2013-5144 affects Apple iOS versions prior to 7.0.3, including 7.0, 7.0.1, and 7.0.2.
Who can exploit CVE-2013-5144?
CVE-2013-5144 can be exploited by physically proximate attackers who have the ability to interact with the device while it is in a specific notification and camera-pane state.
What is the nature of the vulnerability in CVE-2013-5144?
CVE-2013-5144 allows attackers to bypass the passcode lock and make arbitrary phone calls by exploiting a NULL pointer dereference.