CVE Database
/

CVE-2013-3954

Back to search

CVE-2013-3954

Published: Jun 5, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

The posix_spawn system call in the XNU kernel in Apple Mac OS X 10.8.x does not properly validate the data for file actions and port actions, which allows local users to (1) cause a denial of service (panic) via a size value that is inconsistent with a header count field, or (2) obtain sensitive information from kernel heap memory via a certain size value in conjunction with a crafted buffer.

VendorProductVersions

n/a

n/a

affected
n/a

References

1029054
vdb-entry
x_refsource_SECTRACK
APPLE-SA-2013-10-22-3
vendor-advisory
x_refsource_APPLE
54886
third-party-advisory
x_refsource_SECUNIA
APPLE-SA-2013-09-18-2
vendor-advisory
x_refsource_APPLE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now