IOKit in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 places kernel pointers into an object data structure, which makes it easier for local users to bypass the ASLR protection mechanism by reading unspecified attributes of the object.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
21 Nov 2024, 02:04
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/bugtraq/2014-04/0134.html - | |
References | () http://archives.neohapsis.com/archives/bugtraq/2014-04/0135.html - | |
References | () http://archives.neohapsis.com/archives/bugtraq/2014-04/0136.html - |
Information
Published : 2014-04-23 11:52
Updated : 2024-11-21 02:04
NVD link : CVE-2014-1320
Mitre link : CVE-2014-1320
CVE.ORG link : CVE-2014-1320
JSON object : View
Products Affected
apple
- iphone_os
- tvos
- mac_os_x
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor