Lucene search

K
nessusTenable6615.PRM
HistoryNov 06, 2012 - 12:00 a.m.

Apple iOS < 6.0.1 Multiple Vulnerabilities

2012-11-0600:00:00
Tenable
www.tenable.com
13

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.204

Percentile

96.5%

According to its banner, the remote Apple iOS device is missing a security update. It is, therefore, affected by the following vulnerabilities :

  • Kernel extension API responses containing an ‘OSBundleMachOHeaders’ key may include kernel addresses which can aid in further attacks. (CVE-2012-3749)
  • The lock screen can provide ‘Passbook’ data to an attacker having physical device access but not a passcode. (CVE-2012-3750)
  • A ‘time-of-check-to-time-of-use’ issue in the handling of JavaScript array data within WebKit could lead to arbitrary, remote code execution. (CVE-2012-3748)
  • A use-after-free issue in the handling of SVG images in WebKit could lead to arbitrary, remote code execution. (CVE-2012-5112)
Binary data 6615.prm

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.204

Percentile

96.5%