First published: Tue Jul 01 2014(Updated: )
Graphics Driver in Apple OS X before 10.9.4 does not properly restrict read operations during processing of an unspecified system call, which allows local users to obtain sensitive information from kernel memory and bypass the ASLR protection mechanism via a crafted call.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | <=10.9.3 | |
Apple iOS and macOS | =10.8.0 | |
Apple iOS and macOS | =10.8.1 | |
Apple iOS and macOS | =10.8.2 | |
Apple iOS and macOS | =10.8.3 | |
Apple iOS and macOS | =10.8.4 | |
Apple iOS and macOS | =10.8.5 | |
Apple iOS and macOS | =10.8.5-supplemental_update | |
Apple iOS and macOS | =10.9 | |
Apple iOS and macOS | =10.9.1 | |
Apple iOS and macOS | =10.9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1372 has been classified with a high severity due to its potential for local users to access sensitive kernel memory.
To resolve CVE-2014-1372, update your Mac OS X to version 10.9.4 or later.
CVE-2014-1372 affects local users on Apple OS X versions prior to 10.9.4, including versions 10.8 and 10.9.
CVE-2014-1372 is a local information disclosure vulnerability that compromises kernel memory protection.
CVE-2014-1372 cannot be exploited remotely as it requires local user access.