The extensions APIs in the kernel in Apple iOS before 6.0.1 provide kernel addresses in responses that contain an OSBundleMachOHeaders key, which makes it easier for remote attackers to bypass the ASLR protection mechanism via a crafted app.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/56361 | vdb entry |
http://secunia.com/advisories/51445 | third party advisory |
http://support.apple.com/kb/HT5567 | vendor advisory |
http://lists.apple.com/archives/security-announce/2012/Nov/msg00000.html | vendor advisory |
http://lists.apple.com/archives/security-announce/2013/Mar/msg00002.html | vendor advisory |
http://archives.neohapsis.com/archives/bugtraq/2012-11/0012.html | mailing list |
http://support.apple.com/kb/HT5598 |