Release date:
Updated on: 2013-01-31
Affected Systems:
Apple iPhone 4.x
Apple iPhone 3.x
Apple iOS 3.x
Apple iOS 2.x
Apple TV 5.x
Apple TV 4.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57595
CVE (CAN) ID: CVE-2013-0964
Apple iOS is an operating system developed by Apple.
Ios will verify the user State pointer and length passed to the copyin and copyout functions. This verification operation is used to ensure that user State processes cannot directly access the kernel memory. When the passed length is less than one page, the verification operation is bypassed, allowing attackers to access the kernel memory.
<* Source: Mark Dowd
Link: https://support.apple.com/kb/HT5642? Utm_source = feedburner & utm_medium = feed & utm_campaign = Feed % 3A + Cooln
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apple
-----
Apple has released a Security Bulletin (HT5642) and corresponding patches for this:
HT5642: About the security content of iOS 6.1 Software Update
Link: https://support.apple.com/kb/HT5642? Utm_source = feedburner & utm_medium = feed & utm_campaign = Feed % 3A + Cooln