The Bluetooth driver in Apple OS X before 10.10.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (arbitrary-size bzero of kernel memory) via a crafted app.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://code.google.com/p/google-security-research/issues/detail?id=136 | exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/100490 | vdb entry |
http://support.apple.com/HT204244 | vendor advisory |
http://www.securitytracker.com/id/1031626 | vdb entry |
http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.html | vendor advisory |