cbcvebase.
CVE-2013-3951
published 2013-06-05

CVE-2013-3951: sys/openbsd/stack_protector.c in libc in Apple iOS 6.1.3 and Mac OS X 10.8.x does not properly parse the Apple strings employed in the user-space stack-cookie…

PriorityP416medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.46%
37.3th percentile
sys/openbsd/stack_protector.c in libc in Apple iOS 6.1.3 and Mac OS X 10.8.x does not properly parse the Apple strings employed in the user-space stack-cookie implementation, which allows local users to bypass cookie randomization by executing a program with a call-path beginning with the stack-guard= substring, as demonstrated by an iOS untethering attack or an attack against a setuid Mac OS X program.

Affected

12 ranges
VendorProductVersion rangeFixed in
appleios_9
appleiphone_os<= 8.2
appleiphone_os
applemac_os_x<= 10.10.4
applemac_os_x
applemac_os_x
applemac_os_x
applemac_os_x
applemac_os_x
appleos_x_el_capitan_v10.11
applewatchos<= 1.0.1
applewatchos_2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.