Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-3955


The get_xattrinfo function in the XNU kernel in Apple iOS 5.x and 6.x through 6.1.3 on iPad devices does not properly validate the header of an AppleDouble file, which might allow local users to cause a denial of service (memory corruption) or have unspecified other impact via an invalid file on an msdosfs filesystem.


Published

2013-06-05T14:39:57.877

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.2 (MEDIUM)

CVSSv2 Vector

AV:L/AC:H/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: HIGH
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

1.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System apple iphone_os 5.0 Yes
Operating System apple iphone_os 5.0.1 Yes
Operating System apple iphone_os 5.1 Yes
Operating System apple iphone_os 5.1.1 Yes
Operating System apple iphone_os 6.0 Yes
Operating System apple iphone_os 6.0.1 Yes
Operating System apple iphone_os 6.0.2 Yes
Operating System apple iphone_os 6.1 Yes
Operating System apple iphone_os 6.1.2 Yes
Operating System apple iphone_os 6.1.3 Yes
Hardware apple ipad * Yes
Hardware apple ipad_mini - Yes
Hardware apple ipad2 - Yes

References