Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-3749

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2012-3749
Last Modified 17 Aug 2013 02:47:26
Published 03 Nov 2012 01:55:01
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2012-3749

Summary

The extensions APIs in the kernel in Apple iOS before 6.0.1 provide kernel addresses in responses that contain an OSBundleMachOHeaders key, which makes it easier for remote attackers to bypass the ASLR protection mechanism via a crafted app.

Vulnerable Systems

Operating System

  • Apple Iphone Os 1.0.0

  • Apple Iphone Os 1.0.1

  • Apple Iphone Os 1.0.2

  • Apple Iphone Os 1.1.0

  • Apple Iphone Os 1.1.1

  • Apple Iphone Os 1.1.2

  • Apple Iphone Os 1.1.3

  • Apple Iphone Os 1.1.4

  • Apple Iphone Os 1.1.5

  • Apple Iphone Os 2.0

  • Apple Iphone Os 2.0.0

  • Apple Iphone Os 2.0.1

  • Apple Iphone Os 2.0.2

  • Apple Iphone Os 2.1

  • Apple Iphone Os 2.1.1

  • Apple Iphone Os 2.2

  • Apple Iphone Os 2.2.1

  • Apple Iphone Os 3.0

  • Apple Iphone Os 3.0.1

  • Apple Iphone Os 3.1

  • Apple Iphone Os 3.1.2

  • Apple Iphone Os 3.1.3

  • Apple Iphone Os 3.2

  • Apple Iphone Os 3.2.1

  • Apple Iphone Os 3.2.2

  • Apple Iphone Os 4.0

  • Apple Iphone Os 4.0.1

  • Apple Iphone Os 4.0.2

  • Apple Iphone Os 4.1

  • Apple Iphone Os 4.2.1

  • Apple Iphone Os 4.2.5

  • Apple Iphone Os 4.2.8

  • Apple Iphone Os 4.3.0

  • Apple Iphone Os 4.3.1

  • Apple Iphone Os 4.3.2

  • Apple Iphone Os 4.3.3

  • Apple Iphone Os 4.3.5

  • Apple Iphone Os 5.0

  • Apple Iphone Os 5.0.1

  • Apple Iphone Os 5.1.1

  • Apple Iphone Os 6.0


References

CONFIRM - http://support.apple.com/kb/HT5567

APPLE - APPLE-SA-2012-11-01-1

BUGTRAQ - 20121101 APPLE-SA-2012-11-01-1 iOS 6.0.1

BID - 56361

APPLE - APPLE-SA-2013-03-14-1

CONFIRM - http://support.apple.com/kb/HT5598

SECUNIA - 51445

Related Patches

Apple 2013-03-14 Mac OS X 10.8.3 Update (Rev 2)

Apple 2013-03-14 Mac OS X 10.8.3 Combo Update (Rev 3)


Last Updated: 27 May 2016 11:01:22