CVE-2012-3749
CVE-2012-3749
The extensions APIs in the kernel in Apple iOS before 6.0.1 provide kernel addresses in responses that contain an OSBundleMachOHeaders key, which makes it easier for remote attackers to bypass the ASLR protection mechanism via a crafted app.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://archives.neohapsis.com/archives/bugtraq/2012-11/0012.htmlhttp://lists.apple.com/archives/security-announce/2012/Nov/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2013/Mar/msg00002.htmlhttp://secunia.com/advisories/51445http://support.apple.com/kb/HT5567http://support.apple.com/kb/HT5598http://www.securityfocus.com/bid/56361