Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not properly set refresh rates for DDR3 RAM, which might make it easier for remote attackers to conduct row-hammer attacks, and consequently gain privileges or cause a denial of service (memory corruption), by triggering certain patterns of access to memory locations.
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
http://lists.apple.com/archives/security-announce/2015/Jun/msg00003.html | vendor advisory |
http://googleprojectzero.blogspot.com/2015/03/exploiting-dram-rowhammer-bug-to-gain.html | |
http://lists.apple.com/archives/security-announce/2015/Jun/msg00002.html | patch vendor advisory |
http://www.securitytracker.com/id/1032755 | vdb entry |
http://support.apple.com/kb/HT204942 | vendor advisory |
http://www.securityfocus.com/bid/75495 | vdb entry |
http://www.securitytracker.com/id/1032444 | vdb entry |
http://support.apple.com/kb/HT204934 | vendor advisory |