VulnerabilityModified
CVE-2013-0978
The ARM prefetch abort handler in the kernel in Apple iOS before 6.1.3 and Apple TV before 5.2.1 does not ensure that it has been invoked in an abort context, which makes it easier for local users to bypass the ASLR protection mechanism via crafted code.
LOW 2.1EPSS 0.35%
Does this matter?
Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.
Description
The ARM prefetch abort handler in the kernel in Apple iOS before 6.1.3 and Apple TV before 5.2.1 does not ensure that it has been invoked in an abort context, which makes it easier for local users to bypass the ASLR protection mechanism via crafted code.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.35% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- apple/iphone os · apple/tvos
- Source
- product-security@apple.com
References
- http://lists.apple.com/archives/security-announce/2013/Mar/msg00004.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2013/Mar/msg00005.htmlVendor Advisory
- http://support.apple.com/kb/HT5702Vendor Advisory
- http://support.apple.com/kb/HT5704Vendor Advisory
- http://lists.apple.com/archives/security-announce/2013/Mar/msg00004.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2013/Mar/msg00005.htmlVendor Advisory
- http://support.apple.com/kb/HT5702Vendor Advisory
- http://support.apple.com/kb/HT5704Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.