01642 06 11 11 Arrange Call

KASLR Bypass Vulnerability in XNU Kernel on Mac OS X 10.8.x

CVE-2013-3952 · LOW

CVE-2013-3952

The fill_pipeinfo function in bsd/kern/sys_pipe.c in the XNU kernel in Apple Mac OS X 10.8.x allows local users to defeat the KASLR protection mechanism via the PROC_PIDFDPIPEINFO option to the proc_info system call for a kernel pipe handle.

Learn more about our User Device Pen Test.