CVE-2013-0978Sensitive Information Exposure in Apple Iphone OS

Severity
2.1LOWNVD
EPSS
0.1%
top 80.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 20
Latest updateMay 13

Description

The ARM prefetch abort handler in the kernel in Apple iOS before 6.1.3 and Apple TV before 5.2.1 does not ensure that it has been invoked in an abort context, which makes it easier for local users to bypass the ASLR protection mechanism via crafted code.

CVSS vector

AV:L/AC:L/C:P/I:N/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages2 packages

NVDapple/tvos5.2.0+28
NVDapple/iphone_os6.1.2+45

🔴Vulnerability Details

1
GHSA
GHSA-w4wq-5jxq-9m44: The ARM prefetch abort handler in the kernel in Apple iOS before 62022-05-13

💬Community

1
Bugzilla
CVE-2013-2020 CVE-2013-2021 clamav: Multiple potential security issues fixed in upstream 0.97.8 version2013-04-24