The kernel in Apple OS X before 10.9.5 allows local users to obtain sensitive address information and bypass the ASLR protection mechanism by leveraging predictability of the location of the CPU Global Descriptor Table.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/96064 | vdb entry |
http://www.securitytracker.com/id/1030868 | vdb entry |
http://support.apple.com/kb/HT6443 | vendor advisory |
http://www.securityfocus.com/bid/69910 | vdb entry |