ID

VAR-201301-0340


CVE

CVE-2013-0964


TITLE

Apple iOS and Apple TV Vulnerability in the kernel that circumvents pointer restrictions

Trust: 0.8

sources: JVNDB: JVNDB-2013-001315

DESCRIPTION

The kernel in Apple iOS before 6.1 and Apple TV before 5.2 does not properly validate copyin and copyout arguments, which allows local users to bypass intended pointer restrictions and access locations in the first kernel-memory page by specifying a length of less than one page. Apple iOS for the iPhone, the iPod touch, and the iPad is prone to an information disclosure vulnerability. An attacker can exploit this issue to gain access to potentially sensitive information. Apple iOS is an operating system developed by Apple (Apple) for mobile devices. A vulnerability exists in the kernel of Apple iOS versions prior to 6.1 and Apple TV versions prior to 5.2. The vulnerability stems from the fact that the program does not validate the copyin and copyout parameters. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 APPLE-SA-2013-01-28-1 iOS 6.1 Software Update iOS 6.1 Software Update is now available and addresses the following: Identity Services Available for: iPhone 3GS and later, iPod touch (4th generation) and later, iPad 2 and later Impact: Authentication relying on certificate-based Apple ID authentication may be bypassed Description: An error handling issue existed in Identity Services. If the user's AppleID certificate failed to validate, the user's AppleID was assumed to be the empty string. If multiple systems belonging to different users enter this state, applications relying on this identity determination may erroneously extend trust. This issue was addressed by ensuring that NULL is returned instead of an empty string. CVE-ID CVE-2013-0963 International Components for Unicode Available for: iPhone 3GS and later, iPod touch (4th generation) and later, iPad 2 and later Impact: Visiting a maliciously crafted website may lead to a cross- site scripting attack Description: A canonicalization issue existed in the handling of the EUC-JP encoding, which could lead to a cross-site scripting attack on EUC-JP encoded websites. This issue was addressed by updating the EUC-JP mapping table. The checks were not being used if the length was smaller than one page. This issue was addressed through additional validation of the arguments to copyin and copyout. CVE-ID CVE-2013-0964 : Mark Dowd of Azimuth Security Security Available for: iPhone 3GS and later, iPod touch (4th generation) and later, iPad 2 and later Impact: An attacker with a privileged network position may intercept user credentials or other sensitive information Description: Several intermediate CA certificates were mistakenly issued by TURKTRUST. This issue was addressed by not allowing the incorrect SSL certificates. StoreKit Available for: iPhone 3GS and later, iPod touch (4th generation) and later, iPad 2 and later Impact: JavaScript may be enabled in Mobile Safari without user interaction Description: If a user disabled JavaScript in Safari Preferences, visiting a site which displayed a Smart App Banner would re-enable JavaScript without warning the user. This issue was addressed by not enabling JavaScript when visiting a site with a Smart App Banner. CVE-ID CVE-2013-0974 : Andrew Plotkin of Zarfhome Software Consulting, Ben Madison of BitCloud, Marek Durcek WebKit Available for: iPhone 3GS and later, iPod touch (4th generation) and later, iPad 2 and later Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution Description: Multiple memory corruption issues existed in WebKit. These issues were addressed through improved memory handling. CVE-ID CVE-2012-2824 : miaubiz CVE-2012-2857 : Arthur Gerkis CVE-2012-3606 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2012-3607 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2012-3621 : Skylined of the Google Chrome Security Team CVE-2012-3632 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2012-3687 : kuzzcc CVE-2012-3701 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2013-0948 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2013-0949 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2013-0950 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2013-0951 : Apple CVE-2013-0952 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2013-0953 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2013-0954 : Dominic Cooney of Google and Martin Barbella of the Google Chrome Security Team CVE-2013-0955 : Apple CVE-2013-0956 : Apple Product Security CVE-2013-0958 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2013-0959 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2013-0968 : Aaron Nelson WebKit Available for: iPhone 3GS and later, iPod touch (4th generation) and later, iPad 2 and later Impact: Copying and pasting content on a malicious website may lead to a cross-site scripting attack Description: A cross-site scripting issue existed in the handling of content pasted from a different origin. This issue was addressed through additional validation of pasted content. CVE-ID CVE-2013-0962 : Mario Heiderich of Cure53 WebKit Available for: iPhone 3GS and later, iPod touch (4th generation) and later, iPad 2 and later Impact: Visiting a maliciously crafted website may lead to a cross- site scripting attack Description: A cross-site scripting issue existed in the handling of frame elements. This issue was addressed through improved origin tracking. CVE-ID CVE-2012-2889 : Sergey Glazunov WiFi Available for: iPhone 3GS, iPhone 4, iPod touch (4th generation), iPad 2 Impact: A remote attacker on the same WiFi network may be able to temporarily disable WiFi Description: An out of bounds read issue exists in Broadcom's BCM4325 and BCM4329 firmware's handling of 802.11i information elements. This issue was addressed through additional validation of 802.11i information elements. CVE-ID CVE-2012-2619 : Andres Blanco and Matias Eissler of Core Security Installation note: This update is available through iTunes and Software Update on your iOS device, and will not appear in your computer's Software Update application, or in the Apple Downloads site. Make sure you have an Internet connection and have installed the latest version of iTunes from www.apple.com/itunes/ iTunes and Software Update on the device will automatically check Apple's update server on its weekly schedule. When an update is detected, it is downloaded and the option to be installed is presented to the user when the iOS device is docked. We recommend applying the update immediately if possible. Selecting Don't Install will present the option the next time you connect your iOS device. The automatic update process may take up to a week depending on the day that iTunes or the device checks for updates. You may manually obtain the update via the Check for Updates button within iTunes, or the Software Update on your device. The version after applying this update will be "6.1". Information will also be posted to the Apple Security Updates web site: http://support.apple.com/kb/HT1222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.17 (Darwin) Comment: GPGTools - http://gpgtools.org iQIcBAEBAgAGBQJRBffvAAoJEPefwLHPlZEwzYgP/0qhsTft9TUGuphoY9tth5WB D0+8pAKs+1HU+nMOaEKPbK+zdMxblhRNPQyhMuTAQaY5Z/iGn1EXVCTlQBO8esRW epxNZuhFoaW4wzK9kvw5d/HZ9tfq059ozlFOp1TI2D6J5RwNgxDfigt2PUKCTV4X u/BONQHIfINYMofgf5897LHYYFSU2+NJj5ouM5dY4Y/kfJkwAnG5AWCAGlEt3QOo MZdaVv3/itPj4te838FYCVAepel3xBWX0Hhuu87+waHslRrIfQl+EvNk3YZXxWiF O5Hw9Ng/H8n0sbeA39w0U8tw+q/wPhVexdULgRjBH65+6g7Cu5u+rMuYuRjl8fO/ glLhKZNSrQDa5ZNOraOrF62AFVByHaSxv4cZwo262/6uH93FIBtklMt947GMVQLC 1FT0CIGNJb1/0156bvsABfRScBtK9ZdIUjXhOHMinhQJX3qiBqyKc4/juYPmC9VC KXk2/K8b0sGWQRc5RuQsSpzkZF9WcrwmgGOBIghp2DLmbAAj0uh2Ttf1GdrOaajR XpZ2TTJ5qE+IHNU0/etroTYnzjKVjQ0pODrPZj7ALLXULTraXJRJy7fqraUzsHbi AZiRca+3x/S9nqV0NpTNPZgTwxenox10t0w5vhcBK+SPGga1oVRbtOjGtVIkgoG4 KI3sdgb6PtpZWuIJ6iZA =J2jv -----END PGP SIGNATURE-----

Trust: 2.16

sources: NVD: CVE-2013-0964 // JVNDB: JVNDB-2013-001315 // BID: 57595 // VULHUB: VHN-60966 // PACKETSTORM: 119897 // PACKETSTORM: 119898

AFFECTED PRODUCTS

vendor:applemodel:iphone osscope:eqversion:6.0

Trust: 1.6

vendor:applemodel:iphone osscope:eqversion:6.0.1

Trust: 1.6

vendor:applemodel:tvosscope:eqversion:2.0.0

Trust: 1.0

vendor:applemodel:tvosscope:eqversion:4.2.1

Trust: 1.0

vendor:applemodel:tvosscope:eqversion:5.1.0

Trust: 1.0

vendor:applemodel:tvosscope:eqversion:1.0.0

Trust: 1.0

vendor:applemodel:tvosscope:eqversion:4.1.1

Trust: 1.0

vendor:applemodel:iphone osscope:lteversion:6.0.2

Trust: 1.0

vendor:applemodel:tvosscope:eqversion:5.0.0

Trust: 1.0

vendor:applemodel:tvosscope:eqversion:2.4.0

Trust: 1.0

vendor:applemodel:tvosscope:lteversion:5.1.1

Trust: 1.0

vendor:applemodel:tvosscope:eqversion:4.2.0

Trust: 1.0

vendor:applemodel:tvosscope:eqversion:2.3.0

Trust: 1.0

vendor:applemodel:tvosscope:eqversion:2.0.1

Trust: 1.0

vendor:applemodel:tvosscope:eqversion:2.2.0

Trust: 1.0

vendor:applemodel:tvosscope:eqversion:2.3.1

Trust: 1.0

vendor:applemodel:tvosscope:eqversion:3.0.0

Trust: 1.0

vendor:applemodel:tvosscope:eqversion:2.0.2

Trust: 1.0

vendor:applemodel:tvosscope:eqversion:5.0.2

Trust: 1.0

vendor:applemodel:tvosscope:eqversion:4.4.4

Trust: 1.0

vendor:applemodel:tvosscope:eqversion:4.4.2

Trust: 1.0

vendor:applemodel:tvosscope:eqversion:4.4.0

Trust: 1.0

vendor:applemodel:tvosscope:eqversion:2.1.0

Trust: 1.0

vendor:applemodel:tvosscope:eqversion:4.1.0

Trust: 1.0

vendor:applemodel:tvosscope:eqversion:4.2.2

Trust: 1.0

vendor:applemodel:tvosscope:eqversion:3.0.2

Trust: 1.0

vendor:applemodel:tvosscope:eqversion:3.0.1

Trust: 1.0

vendor:applemodel:tvosscope:eqversion:5.0.1

Trust: 1.0

vendor:applemodel:tvosscope:eqversion:4.3.0

Trust: 1.0

vendor:applemodel:tvosscope:eqversion:4.4.3

Trust: 1.0

vendor:applemodel:tvosscope:eqversion:1.1.0

Trust: 1.0

vendor:applemodel:tvscope:eqversion:5.1.1

Trust: 0.9

vendor:applemodel:tvscope:ltversion:5.2 ( first 2 after generation )

Trust: 0.8

vendor:applemodel:iosscope:ltversion:6.1 (ipad 2 or later )

Trust: 0.8

vendor:applemodel:iosscope:ltversion:6.1 (iphone 3gs or later )

Trust: 0.8

vendor:applemodel:iosscope:ltversion:6.1 (ipod touch first 4 after generation )

Trust: 0.8

vendor:applemodel:iphone osscope:eqversion:6.0.2

Trust: 0.6

vendor:applemodel:tvscope:eqversion:3.0.1

Trust: 0.6

vendor:applemodel:tvscope:eqversion:2.2.0

Trust: 0.6

vendor:applemodel:tvscope:eqversion:2.4.0

Trust: 0.6

vendor:applemodel:tvscope:eqversion:3.0.0

Trust: 0.6

vendor:applemodel:tvscope:eqversion:3.0.2

Trust: 0.6

vendor:applemodel:tvscope:eqversion:2.3.1

Trust: 0.6

vendor:applemodel:ipod touchscope:eqversion:3.1.3

Trust: 0.3

vendor:applemodel:ipod touchscope:eqversion:3.1.2

Trust: 0.3

vendor:applemodel:ipod touchscope:eqversion:3.1.1

Trust: 0.3

vendor:applemodel:ipod touchscope:eqversion:3.0

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:4.3.3

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:4.0.1

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:3.2.1

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:3.1.3

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:3.1.2

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:3.0.1

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:4.3.2

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:4.3.1

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:4.3.0

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:4.2.8

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:4.2.5

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:4.2.1

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:4.1

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:4.0.2

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:4.0

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:3.2.2

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:3.2

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:3.1

Trust: 0.3

vendor:applemodel:ipadscope:eqversion:3.2.1

Trust: 0.3

vendor:applemodel:ipadscope:eqversion:3.2.2

Trust: 0.3

vendor:applemodel:ipadscope:eqversion:3.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.0.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:6.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:6

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.1.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.9

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.8

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.7

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.6

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.10

Trust: 0.3

vendor:applemodel:ios betascope:eqversion:4.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.0

Trust: 0.3

vendor:applemodel:iosscope:eqversion:2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:2.0

Trust: 0.3

vendor:applemodel:tvscope:eqversion:5.1

Trust: 0.3

vendor:applemodel:tvscope:eqversion:5.0

Trust: 0.3

vendor:applemodel:tvscope:eqversion:4.4

Trust: 0.3

vendor:applemodel:tvscope:eqversion:4.3

Trust: 0.3

vendor:applemodel:tvscope:eqversion:4.2

Trust: 0.3

vendor:applemodel:tvscope:eqversion:4.1

Trust: 0.3

vendor:applemodel:tvscope:eqversion:4.0

Trust: 0.3

vendor:applemodel:iosscope:neversion:6.1

Trust: 0.3

vendor:applemodel:tvscope:neversion:5.2

Trust: 0.3

sources: BID: 57595 // JVNDB: JVNDB-2013-001315 // CNNVD: CNNVD-201301-559 // NVD: CVE-2013-0964

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-0964
value: LOW

Trust: 1.0

NVD: CVE-2013-0964
value: LOW

Trust: 0.8

CNNVD: CNNVD-201301-559
value: LOW

Trust: 0.6

VULHUB: VHN-60966
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2013-0964
severity: LOW
baseScore: 3.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-60966
severity: LOW
baseScore: 3.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-60966 // JVNDB: JVNDB-2013-001315 // CNNVD: CNNVD-201301-559 // NVD: CVE-2013-0964

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-60966 // JVNDB: JVNDB-2013-001315 // NVD: CVE-2013-0964

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201301-559

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201301-559

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-001315

PATCH

title:APPLE-SA-2013-01-28-2url:http://lists.apple.com/archives/security-announce/2013/Jan/msg00001.html

Trust: 0.8

title:APPLE-SA-2013-01-28-1url:http://lists.apple.com/archives/security-announce/2013/Jan/msg00000.html

Trust: 0.8

title:HT5642url:http://support.apple.com/kb/HT5642

Trust: 0.8

title:HT5643url:http://support.apple.com/kb/HT5643

Trust: 0.8

title:HT5642url:http://support.apple.com/kb/HT5642?viewlocale=ja_JP

Trust: 0.8

title:HT5643url:http://support.apple.com/kb/HT5643?viewlocale=ja_JP

Trust: 0.8

title:Apple iOS/Apple TV Fixes for kernel security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=90755

Trust: 0.6

sources: JVNDB: JVNDB-2013-001315 // CNNVD: CNNVD-201301-559

EXTERNAL IDS

db:NVDid:CVE-2013-0964

Trust: 3.0

db:BIDid:57595

Trust: 2.0

db:OSVDBid:89659

Trust: 1.7

db:JVNDBid:JVNDB-2013-001315

Trust: 0.8

db:CNNVDid:CNNVD-201301-559

Trust: 0.7

db:VULHUBid:VHN-60966

Trust: 0.1

db:PACKETSTORMid:119897

Trust: 0.1

db:PACKETSTORMid:119898

Trust: 0.1

sources: VULHUB: VHN-60966 // BID: 57595 // JVNDB: JVNDB-2013-001315 // PACKETSTORM: 119897 // PACKETSTORM: 119898 // CNNVD: CNNVD-201301-559 // NVD: CVE-2013-0964

REFERENCES

url:http://support.apple.com/kb/ht5642

Trust: 2.0

url:http://support.apple.com/kb/ht5643

Trust: 2.0

url:http://lists.apple.com/archives/security-announce/2013/jan/msg00000.html

Trust: 1.7

url:http://lists.apple.com/archives/security-announce/2013/jan/msg00001.html

Trust: 1.7

url:http://www.securityfocus.com/bid/57595

Trust: 1.7

url:http://osvdb.org/89659

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-0964

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-0964

Trust: 0.8

url:http://www.apple.com/iphone/softwareupdate/

Trust: 0.3

url:http://www.apple.com/ipad/

Trust: 0.3

url:http://www.apple.com/iphone/

Trust: 0.3

url:http://www.apple.com/ipodtouch/

Trust: 0.3

url:http://support.apple.com/kb/ht1222

Trust: 0.2

url:https://www.apple.com/support/security/pgp/

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2012-2619

Trust: 0.2

url:http://gpgtools.org

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2013-0964

Trust: 0.2

url:https://www.apple.com/itunes/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0956

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3687

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3632

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0954

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0955

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0948

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-2889

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3621

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0959

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0952

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0958

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3701

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0949

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0962

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0968

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-3058

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-2857

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0950

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0951

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0974

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-2824

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0953

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3606

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3607

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0963

Trust: 0.1

sources: VULHUB: VHN-60966 // BID: 57595 // JVNDB: JVNDB-2013-001315 // PACKETSTORM: 119897 // PACKETSTORM: 119898 // CNNVD: CNNVD-201301-559 // NVD: CVE-2013-0964

CREDITS

Mario Heiderich of Cure53, Andrew Plotkin of Zarfhome Software Consulting, Marek Durcek, Apple Product Security,Mark Dowd of Azimuth Security, Ben Madison of BitCloud, Abhishek Arya (Inferno) of the Google Chrome Security Team, Aaron Nelson

Trust: 0.6

sources: CNNVD: CNNVD-201301-559

SOURCES

db:VULHUBid:VHN-60966
db:BIDid:57595
db:JVNDBid:JVNDB-2013-001315
db:PACKETSTORMid:119897
db:PACKETSTORMid:119898
db:CNNVDid:CNNVD-201301-559
db:NVDid:CVE-2013-0964

LAST UPDATE DATE

2025-04-11T20:48:11.103000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-60966date:2019-03-08T00:00:00
db:BIDid:57595date:2013-01-28T00:00:00
db:JVNDBid:JVNDB-2013-001315date:2013-01-30T00:00:00
db:CNNVDid:CNNVD-201301-559date:2019-03-13T00:00:00
db:NVDid:CVE-2013-0964date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:VULHUBid:VHN-60966date:2013-01-29T00:00:00
db:BIDid:57595date:2013-01-28T00:00:00
db:JVNDBid:JVNDB-2013-001315date:2013-01-30T00:00:00
db:PACKETSTORMid:119897date:2013-01-30T02:53:29
db:PACKETSTORMid:119898date:2013-01-30T02:58:08
db:CNNVDid:CNNVD-201301-559date:2013-01-30T00:00:00
db:NVDid:CVE-2013-0964date:2013-01-29T05:58:54.930