CVE-2013-3951
published 2013-06-05CVE-2013-3951: sys/openbsd/stack_protector.c in libc in Apple iOS 6.1.3 and Mac OS X 10.8.x does not properly parse the Apple strings employed in the user-space stack-cookie…
PriorityP416medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.46%
37.3th percentile
sys/openbsd/stack_protector.c in libc in Apple iOS 6.1.3 and Mac OS X 10.8.x does not properly parse the Apple strings employed in the user-space stack-cookie implementation, which allows local users to bypass cookie randomization by executing a program with a call-path beginning with the stack-guard= substring, as demonstrated by an iOS untethering attack or an attack against a setuid Mac OS X program.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_9 | — | — |
| apple | iphone_os | <= 8.2 | — |
| apple | iphone_os | — | — |
| apple | mac_os_x | <= 10.10.4 | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | os_x_el_capitan_v10.11 | — | — |
| apple | watchos | <= 1.0.1 | — |
| apple | watchos_2 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-77m7-6q2g-65ff: sys/openbsd/stack_protector
ghsa_unreviewed·2022-05-17
CVE-2013-3951 [MEDIUM] CWE-20 GHSA-77m7-6q2g-65ff: sys/openbsd/stack_protector
sys/openbsd/stack_protector.c in libc in Apple iOS 6.1.3 and Mac OS X 10.8.x does not properly parse the Apple strings employed in the user-space stack-cookie implementation, which allows local users to bypass cookie randomization by executing a program with a call-path beginning with the stack-guard= substring, as demonstrated by an iOS untethering attack or an attack against a setuid Mac OS X program.
Apple
CVE-2013-3951: watchOS 2
vendor_apple·CVSS 4.6
CVE-2013-3951 [MEDIUM] CVE-2013-3951: watchOS 2
Apple Security Update: About the security content of watchOS 2
Product: watchOS 2
CVE: CVE-2013-3951
Component: CVE-ID
Apple
CVE-2013-3951: iOS 9
vendor_apple·CVSS 4.6
CVE-2013-3951 [MEDIUM] CVE-2013-3951: iOS 9
Apple Security Update: About the security content of iOS 9
Product: iOS 9
CVE: CVE-2013-3951
Component: CVE-ID
Apple
CVE-2013-3951: OS X El Capitan v10.11
vendor_apple·CVSS 4.6
CVE-2013-3951 [MEDIUM] CVE-2013-3951: OS X El Capitan v10.11
Apple Security Update: About the security content of OS X El Capitan v10.11
Product: OS X El Capitan v10.11
CVE: CVE-2013-3951
Component: CVE-ID
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://antid0te.com/syscan_2013/SyScan2013_Mountain_Lion_iOS_Vulnerabilities_Garage_Sale_Whitepaper.pdfhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00005.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlhttp://www.securitytracker.com/id/1033703http://www.syscan.org/index.php/sg/program/day/2https://support.apple.com/HT205212https://support.apple.com/HT205213https://support.apple.com/HT205267http://antid0te.com/syscan_2013/SyScan2013_Mountain_Lion_iOS_Vulnerabilities_Garage_Sale_Whitepaper.pdfhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00005.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlhttp://www.securitytracker.com/id/1033703http://www.syscan.org/index.php/sg/program/day/2https://support.apple.com/HT205212https://support.apple.com/HT205213https://support.apple.com/HT205267
2013-06-05
Published