存在于iPhone3GS、iPod Touch4、iPad2之后的设备
影响:本地用户可在内核中执行任意代码
说明:USB与I/O的驱动程序中,有内存指针验证不完全
USB
Available for: iPhone 3GS and later,
iPod touch (4th generation) and later, iPad 2 and later
Impact: A local user may be able to execute arbitrary code in the
kernel
Description: The IOUSBDeviceFamily driver used pipe object pointers
that came from userspace. This issue was addressed by performing
additional validation of pipe object pointers.
CVE-ID
CVE-2013-0981 : evad3rs
No comments:
Post a Comment