VulnerabilityModified
CVE-2013-0977
dyld in Apple iOS before 6.1.3 and Apple TV before 5.2.1 does not properly manage the state of file loading for Mach-O executable files, which allows local users to bypass intended code-signing requirements via a file that contains overlapping segments.
MEDIUM 4.6EPSS 0.35%
Does this matter?
Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.
Description
dyld in Apple iOS before 6.1.3 and Apple TV before 5.2.1 does not properly manage the state of file loading for Mach-O executable files, which allows local users to bypass intended code-signing requirements via a file that contains overlapping segments.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.35% probability · 28th percentile
- CISA KEV
- Not listed
- Affected
- apple/iphone os · apple/tvos
- Source
- product-security@apple.com
References
- http://lists.apple.com/archives/security-announce/2013/Mar/msg00004.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2013/Mar/msg00005.htmlVendor Advisory
- http://support.apple.com/kb/HT5702Vendor Advisory
- http://support.apple.com/kb/HT5704Vendor Advisory
- http://lists.apple.com/archives/security-announce/2013/Mar/msg00004.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2013/Mar/msg00005.htmlVendor Advisory
- http://support.apple.com/kb/HT5702Vendor Advisory
- http://support.apple.com/kb/HT5704Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.