VulnerabilityModified
CVE-2013-5142
The kernel in Apple iOS before 7 does not initialize unspecified kernel data structures, which allows local users to obtain sensitive information from kernel stack memory via the (1) msgctl API or (2) segctl API.
MEDIUM 4.9EPSS 0.35%
Does this matter?
Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.
Description
The kernel in Apple iOS before 7 does not initialize unspecified kernel data structures, which allows local users to obtain sensitive information from kernel stack memory via the (1) msgctl API or (2) segctl API.
- CVSS 2.0
- 4.9 MEDIUMAV:L/AC:L/Au:N/C:C/I:N/A:N
- EPSS
- 0.35% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- apple/iphone os
- Source
- product-security@apple.com
References
- http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html
- http://lists.apple.com/archives/security-announce/2013/Sep/msg00006.htmlVendor Advisory
- http://support.apple.com/kb/HT5934Vendor Advisory
- http://www.securitytracker.com/id/1029054
- http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html
- http://lists.apple.com/archives/security-announce/2013/Sep/msg00006.htmlVendor Advisory
- http://support.apple.com/kb/HT5934Vendor Advisory
- http://www.securitytracker.com/id/1029054
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.