Vulnerability Name: | CVE-2012-3749 (CCN-79746) |
Assigned: | 2012-11-01 |
Published: | 2012-11-01 |
Updated: | 2013-08-17 |
Summary: | The extensions APIs in the kernel in Apple iOS before 6.0.1 provide kernel addresses in responses that contain an OSBundleMachOHeaders key, which makes it easier for remote attackers to bypass the ASLR protection mechanism via a crafted app.
|
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): Low Integrity (I): None Availibility (A): None |
|
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): None | Impact Metrics: | Confidentiality (C): Partial Integrity (I): None Availibility (A): None | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Athentication (Au): None
| Impact Metrics: | Confidentiality (C): Partial Integrity (I): None Availibility (A): None |
|
Vulnerability Type: | CWE-200
|
Vulnerability Consequences: | Obtain Information |
References: | Source: BUGTRAQ Type: UNKNOWN 20121101 APPLE-SA-2012-11-01-1 iOS 6.0.1
Source: MITRE Type: CNA CVE-2012-3749
Source: APPLE Type: Vendor Advisory APPLE-SA-2012-11-01-1
Source: APPLE Type: UNKNOWN APPLE-SA-2013-03-14-1
Source: CCN Type: SA51445 Apple TV Two Vulnerabilities
Source: SECUNIA Type: UNKNOWN 51445
Source: CONFIRM Type: Vendor Advisory http://support.apple.com/kb/HT5567
Source: CCN Type: Apple KB HT5598 About the security content of Apple TV 5.1.1
Source: CONFIRM Type: UNKNOWN http://support.apple.com/kb/HT5598
Source: CCN Type: Apple Web site About the security content of OS X Mountain Lion v10.8.3 and Security Update 2013-001
Source: CCN Type: OSVDB ID: 86871 Apple iOS Kernel API Handling OSBundleMachOHeaders Key Disclosure
Source: BID Type: UNKNOWN 56361
Source: CCN Type: BID-56361 Apple iPhone/iPad/iPod touch Prior to iOS 6.0.1 CVE-2012-3749 Information Disclosure Vulnerability
Source: XF Type: UNKNOWN appleios-kernel-info-disclosure(79746)
|
Vulnerable Configuration: | Configuration 1: cpe:/o:apple:iphone_os:1.0.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.0.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.0.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.3:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.4:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.5:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.1.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.2.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.0.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.1.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.1.3:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.2.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.2.2:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.0:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.0.1:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.0.2:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.1:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.2.1:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.2.5:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.2.8:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.3.0:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.3.1:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.3.2:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.3.3:*:*:*:*:*:*:*OR cpe:/o:apple:ios:4.3.5:*:*:*:*:*:*:*OR cpe:/o:apple:ios:5.0:*:*:*:*:*:*:*OR cpe:/o:apple:ios:5.0.1:*:*:*:*:*:*:*OR cpe:/o:apple:ios:5.1.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:*:*:*:*:*:*:*:* (Version <= 6.0) Configuration CCN 1: cpe:/o:apple:mac_os_x:10.6.8:*:*:*:*:*:*:*OR cpe:/o:apple:mac_os_x_server:10.6.8:*:*:*:*:*:*:*
Denotes that component is vulnerable |
BACK |