ID

VAR-201301-0402


CVE

CVE-2013-0955


TITLE

Apple iOS and Apple Safari Used in WebKit Vulnerable to arbitrary code execution

Trust: 0.8

sources: JVNDB: JVNDB-2013-001309

DESCRIPTION

WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1. Note: This issue was previously covered in BID 57572 (Apple iPhone/iPad/iPod touch Prior to iOS 6.1 Multiple Vulnerabilities), but has been given its own record to better document it. Apple iOS for the iPhone, the iPod touch, and the iPad is prone to multiple security vulnerabilities. Other attacks are also possible. This BID is being retired. Apple iOS is an operating system developed by Apple (Apple) for mobile devices. CVE-ID CVE-2013-0962 : Mario Heiderich of Cure53 For OS X Lion systems Safari 6.0.3 is available via the Apple Software Update application. For OS X Mountain Lion systems Safari 6.0.3 is included with OS X v10.8.3. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 APPLE-SA-2013-01-28-1 iOS 6.1 Software Update iOS 6.1 Software Update is now available and addresses the following: Identity Services Available for: iPhone 3GS and later, iPod touch (4th generation) and later, iPad 2 and later Impact: Authentication relying on certificate-based Apple ID authentication may be bypassed Description: An error handling issue existed in Identity Services. If the user's AppleID certificate failed to validate, the user's AppleID was assumed to be the empty string. If multiple systems belonging to different users enter this state, applications relying on this identity determination may erroneously extend trust. This issue was addressed by ensuring that NULL is returned instead of an empty string. CVE-ID CVE-2013-0963 International Components for Unicode Available for: iPhone 3GS and later, iPod touch (4th generation) and later, iPad 2 and later Impact: Visiting a maliciously crafted website may lead to a cross- site scripting attack Description: A canonicalization issue existed in the handling of the EUC-JP encoding, which could lead to a cross-site scripting attack on EUC-JP encoded websites. This issue was addressed by updating the EUC-JP mapping table. CVE-ID CVE-2011-3058 : Masato Kinugawa Kernel Available for: iPhone 3GS and later, iPod touch (4th generation) and later, iPad 2 and later Impact: A user-mode process may be able to access the first page of kernel memory Description: The iOS kernel has checks to validate that the user- mode pointer and length passed to the copyin and copyout functions would not result in a user-mode process being able to directly access kernel memory. The checks were not being used if the length was smaller than one page. This issue was addressed through additional validation of the arguments to copyin and copyout. CVE-ID CVE-2013-0964 : Mark Dowd of Azimuth Security Security Available for: iPhone 3GS and later, iPod touch (4th generation) and later, iPad 2 and later Impact: An attacker with a privileged network position may intercept user credentials or other sensitive information Description: Several intermediate CA certificates were mistakenly issued by TURKTRUST. This may allow a man-in-the-middle attacker to redirect connections and intercept user credentials or other sensitive information. This issue was addressed by not allowing the incorrect SSL certificates. StoreKit Available for: iPhone 3GS and later, iPod touch (4th generation) and later, iPad 2 and later Impact: JavaScript may be enabled in Mobile Safari without user interaction Description: If a user disabled JavaScript in Safari Preferences, visiting a site which displayed a Smart App Banner would re-enable JavaScript without warning the user. This issue was addressed by not enabling JavaScript when visiting a site with a Smart App Banner. CVE-ID CVE-2013-0974 : Andrew Plotkin of Zarfhome Software Consulting, Ben Madison of BitCloud, Marek Durcek WebKit Available for: iPhone 3GS and later, iPod touch (4th generation) and later, iPad 2 and later Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution Description: Multiple memory corruption issues existed in WebKit. These issues were addressed through improved memory handling. CVE-ID CVE-2012-2824 : miaubiz CVE-2012-2857 : Arthur Gerkis CVE-2012-3606 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2012-3607 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2012-3621 : Skylined of the Google Chrome Security Team CVE-2012-3632 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2012-3687 : kuzzcc CVE-2012-3701 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2013-0948 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2013-0949 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2013-0950 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2013-0951 : Apple CVE-2013-0952 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2013-0953 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2013-0954 : Dominic Cooney of Google and Martin Barbella of the Google Chrome Security Team CVE-2013-0955 : Apple CVE-2013-0956 : Apple Product Security CVE-2013-0958 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2013-0959 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2013-0968 : Aaron Nelson WebKit Available for: iPhone 3GS and later, iPod touch (4th generation) and later, iPad 2 and later Impact: Copying and pasting content on a malicious website may lead to a cross-site scripting attack Description: A cross-site scripting issue existed in the handling of content pasted from a different origin. This issue was addressed through additional validation of pasted content. CVE-ID CVE-2013-0962 : Mario Heiderich of Cure53 WebKit Available for: iPhone 3GS and later, iPod touch (4th generation) and later, iPad 2 and later Impact: Visiting a maliciously crafted website may lead to a cross- site scripting attack Description: A cross-site scripting issue existed in the handling of frame elements. This issue was addressed through improved origin tracking. CVE-ID CVE-2012-2889 : Sergey Glazunov WiFi Available for: iPhone 3GS, iPhone 4, iPod touch (4th generation), iPad 2 Impact: A remote attacker on the same WiFi network may be able to temporarily disable WiFi Description: An out of bounds read issue exists in Broadcom's BCM4325 and BCM4329 firmware's handling of 802.11i information elements. This issue was addressed through additional validation of 802.11i information elements. CVE-ID CVE-2012-2619 : Andres Blanco and Matias Eissler of Core Security Installation note: This update is available through iTunes and Software Update on your iOS device, and will not appear in your computer's Software Update application, or in the Apple Downloads site. Make sure you have an Internet connection and have installed the latest version of iTunes from www.apple.com/itunes/ iTunes and Software Update on the device will automatically check Apple's update server on its weekly schedule. When an update is detected, it is downloaded and the option to be installed is presented to the user when the iOS device is docked. We recommend applying the update immediately if possible. Selecting Don't Install will present the option the next time you connect your iOS device. The automatic update process may take up to a week depending on the day that iTunes or the device checks for updates. You may manually obtain the update via the Check for Updates button within iTunes, or the Software Update on your device. The version after applying this update will be "6.1". Information will also be posted to the Apple Security Updates web site: http://support.apple.com/kb/HT1222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.17 (Darwin) Comment: GPGTools - http://gpgtools.org iQIcBAEBAgAGBQJRBffvAAoJEPefwLHPlZEwzYgP/0qhsTft9TUGuphoY9tth5WB D0+8pAKs+1HU+nMOaEKPbK+zdMxblhRNPQyhMuTAQaY5Z/iGn1EXVCTlQBO8esRW epxNZuhFoaW4wzK9kvw5d/HZ9tfq059ozlFOp1TI2D6J5RwNgxDfigt2PUKCTV4X u/BONQHIfINYMofgf5897LHYYFSU2+NJj5ouM5dY4Y/kfJkwAnG5AWCAGlEt3QOo MZdaVv3/itPj4te838FYCVAepel3xBWX0Hhuu87+waHslRrIfQl+EvNk3YZXxWiF O5Hw9Ng/H8n0sbeA39w0U8tw+q/wPhVexdULgRjBH65+6g7Cu5u+rMuYuRjl8fO/ glLhKZNSrQDa5ZNOraOrF62AFVByHaSxv4cZwo262/6uH93FIBtklMt947GMVQLC 1FT0CIGNJb1/0156bvsABfRScBtK9ZdIUjXhOHMinhQJX3qiBqyKc4/juYPmC9VC KXk2/K8b0sGWQRc5RuQsSpzkZF9WcrwmgGOBIghp2DLmbAAj0uh2Ttf1GdrOaajR XpZ2TTJ5qE+IHNU0/etroTYnzjKVjQ0pODrPZj7ALLXULTraXJRJy7fqraUzsHbi AZiRca+3x/S9nqV0NpTNPZgTwxenox10t0w5vhcBK+SPGga1oVRbtOjGtVIkgoG4 KI3sdgb6PtpZWuIJ6iZA =J2jv -----END PGP SIGNATURE----- . ---------------------------------------------------------------------- The final version of the CSI 6.0 has been released. Find out why this is not just another Patch Management solution: http://secunia.com/blog/325/ ---------------------------------------------------------------------- TITLE: Apple iOS Multiple Vulnerabilities SECUNIA ADVISORY ID: SA52002 VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/52002/ Customer Area (Credentials Required) https://ca.secunia.com/?page=viewadvisory&vuln_id=52002 RELEASE DATE: 2013-01-29 DISCUSS ADVISORY: http://secunia.com/advisories/52002/#comments AVAILABLE ON SITE AND IN CUSTOMER AREA: * Last Update * Popularity * Comments * Criticality Level * Impact * Where * Solution Status * Operating System / Software * CVE Reference(s) http://secunia.com/advisories/52002/ ONLY AVAILABLE IN CUSTOMER AREA: * Authentication Level * Report Reliability * Secunia PoC * Secunia Analysis * Systems Affected * Approve Distribution * Remediation Status * Secunia CVSS Score * CVSS https://ca.secunia.com/?page=viewadvisory&vuln_id=52002 ONLY AVAILABLE WITH SECUNIA CSI AND SECUNIA PSI: * AUTOMATED SCANNING http://secunia.com/vulnerability_scanning/personal/ http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/ DESCRIPTION: Two security issues and multiple vulnerabilities have been reported in Apple iOS, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, and compromise a user's device. 1) An error when handling a validation failure of a AppleID certificate within the IdentityService can be exploited to potentially bypass the certificate-based AppleID authentication via an invalid AppleID certificate. 2) An error exists in International Components for Unicode. 5) Multiple vulnerabilities are caused due to a bundled vulnerable version of WebKit. 18) Certain input pasted from a different origin is not properly sanitised in WebKit before being used. 19) Certain unspecified input related to frame handling is not properly sanitised before being returned to the user. For more information see vulnerability #1 in: SA50759 NOTE: Additionally a weakness exists within the handling of 802.11i information elements within Broadcom's BCM4325 and BCM4329 firmware, which can be exploited to disable WiFi. PROVIDED AND/OR DISCOVERED BY: 1, 9, 13, and 14) Reported by the vendor The vendor credits: 3) Mark Dowd, Azimuth Security 4) Andrew Plotkin, Zarfhome Software Consulting, Ben Madison, BitCloud, and Marek Durcek 6, 7, 8, 10, 11, 15, and 16) Abhishek Arya (Inferno), Google Chrome Security Team 12) Dominic Cooney, Google and Martin Barbella, Google Chrome Security Team 17) Aaron Nelson 18) Mario Heiderich, Cure53 ORIGINAL ADVISORY: APPLE-SA-2013-01-28-1: http://support.apple.com/kb/HT5642 OTHER REFERENCES: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ DEEP LINKS: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED DESCRIPTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED SOLUTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXPLOIT: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ---------------------------------------------------------------------- . In certain contexts, an active network attacker could present untrusted certificates to iTunes and they would be accepted without warning

Trust: 2.61

sources: NVD: CVE-2013-0955 // JVNDB: JVNDB-2013-001309 // BID: 57587 // BID: 57572 // VULHUB: VHN-60957 // PACKETSTORM: 120821 // PACKETSTORM: 119897 // PACKETSTORM: 119887 // PACKETSTORM: 121672

AFFECTED PRODUCTS

vendor:applemodel:iphone osscope:eqversion:6.0.1

Trust: 1.6

vendor:applemodel:iphone osscope:eqversion:6.0

Trust: 1.6

vendor:applemodel:iphone osscope:lteversion:6.0.2

Trust: 1.0

vendor:applemodel:iosscope:ltversion:6.1 (ipad 2 or later )

Trust: 0.8

vendor:applemodel:iosscope:ltversion:6.1 (iphone 3gs or later )

Trust: 0.8

vendor:applemodel:iosscope:ltversion:6.1 (ipod touch first 4 after generation )

Trust: 0.8

vendor:applemodel:itunesscope:ltversion:11.0.3 (windows)

Trust: 0.8

vendor:applemodel:safariscope:ltversion:6.0.3

Trust: 0.8

vendor:applemodel:ipod touchscope:eqversion:3.1.2

Trust: 0.6

vendor:applemodel:ipod touchscope:eqversion:3.1.1

Trust: 0.6

vendor:applemodel:ipod touchscope:eqversion:3.0

Trust: 0.6

vendor:applemodel:iphonescope:eqversion:4.0.1

Trust: 0.6

vendor:applemodel:iphonescope:eqversion:3.2.1

Trust: 0.6

vendor:applemodel:iphonescope:eqversion:3.1.3

Trust: 0.6

vendor:applemodel:iphonescope:eqversion:3.1.2

Trust: 0.6

vendor:applemodel:iphonescope:eqversion:3.0.1

Trust: 0.6

vendor:applemodel:iphonescope:eqversion:4.3.3

Trust: 0.6

vendor:applemodel:iphonescope:eqversion:4.3.2

Trust: 0.6

vendor:applemodel:iphonescope:eqversion:4.3.1

Trust: 0.6

vendor:applemodel:iphonescope:eqversion:4.3.0

Trust: 0.6

vendor:applemodel:iphonescope:eqversion:4.2.8

Trust: 0.6

vendor:applemodel:iphonescope:eqversion:4.2.5

Trust: 0.6

vendor:applemodel:iphonescope:eqversion:4.2.1

Trust: 0.6

vendor:applemodel:iphonescope:eqversion:4.1

Trust: 0.6

vendor:applemodel:iphonescope:eqversion:4.0.2

Trust: 0.6

vendor:applemodel:iphonescope:eqversion:4.0

Trust: 0.6

vendor:applemodel:iphonescope:eqversion:3.2.2

Trust: 0.6

vendor:applemodel:iphonescope:eqversion:3.2

Trust: 0.6

vendor:applemodel:iphonescope:eqversion:3.1

Trust: 0.6

vendor:applemodel:ipadscope:eqversion:3.2.1

Trust: 0.6

vendor:applemodel:ipadscope:eqversion:3.2.2

Trust: 0.6

vendor:applemodel:ipadscope:eqversion:3.2

Trust: 0.6

vendor:applemodel:iosscope:eqversion:4.2.1

Trust: 0.6

vendor:applemodel:iosscope:eqversion:4.0.2

Trust: 0.6

vendor:applemodel:iosscope:eqversion:4.0.1

Trust: 0.6

vendor:applemodel:iosscope:eqversion:3.2.2

Trust: 0.6

vendor:applemodel:iosscope:eqversion:3.2.1

Trust: 0.6

vendor:applemodel:iosscope:eqversion:5.1.1

Trust: 0.6

vendor:applemodel:iosscope:eqversion:5.1

Trust: 0.6

vendor:applemodel:iosscope:eqversion:5.0.1

Trust: 0.6

vendor:applemodel:iosscope:eqversion:5

Trust: 0.6

vendor:applemodel:iosscope:eqversion:4.3.5

Trust: 0.6

vendor:applemodel:iosscope:eqversion:4.3.4

Trust: 0.6

vendor:applemodel:iosscope:eqversion:4.3.3

Trust: 0.6

vendor:applemodel:iosscope:eqversion:4.3.2

Trust: 0.6

vendor:applemodel:iosscope:eqversion:4.3.1

Trust: 0.6

vendor:applemodel:iosscope:eqversion:4.3

Trust: 0.6

vendor:applemodel:iosscope:eqversion:4.2.9

Trust: 0.6

vendor:applemodel:iosscope:eqversion:4.2.8

Trust: 0.6

vendor:applemodel:iosscope:eqversion:4.2.7

Trust: 0.6

vendor:applemodel:iosscope:eqversion:4.2.6

Trust: 0.6

vendor:applemodel:iosscope:eqversion:4.2.5

Trust: 0.6

vendor:applemodel:iosscope:eqversion:4.2.10

Trust: 0.6

vendor:applemodel:ios betascope:eqversion:4.2

Trust: 0.6

vendor:applemodel:iosscope:eqversion:4.2

Trust: 0.6

vendor:applemodel:iosscope:eqversion:4.1

Trust: 0.6

vendor:applemodel:iosscope:eqversion:4

Trust: 0.6

vendor:applemodel:iosscope:eqversion:3.2

Trust: 0.6

vendor:applemodel:iosscope:eqversion:3.1

Trust: 0.6

vendor:applemodel:iosscope:eqversion:3.0

Trust: 0.6

vendor:applemodel:iosscope:eqversion:2.1

Trust: 0.6

vendor:applemodel:iosscope:eqversion:2.0

Trust: 0.6

vendor:applemodel:iphone osscope:eqversion:6.0.2

Trust: 0.6

vendor:webkitmodel:open source project webkitscope:eqversion:1.2.5

Trust: 0.3

vendor:webkitmodel:open source project webkitscope:eqversion:1.2.3

Trust: 0.3

vendor:webkitmodel:open source project webkitscope:eqversion:1.2.2

Trust: 0.3

vendor:webkitmodel:open source project webkit r82222scope: - version: -

Trust: 0.3

vendor:webkitmodel:open source project webkit r77705scope: - version: -

Trust: 0.3

vendor:webkitmodel:open source project webkit r52833scope: - version: -

Trust: 0.3

vendor:webkitmodel:open source project webkit r52401scope: - version: -

Trust: 0.3

vendor:webkitmodel:open source project webkit r51295scope: - version: -

Trust: 0.3

vendor:webkitmodel:open source project webkit r38566scope: - version: -

Trust: 0.3

vendor:webkitmodel:open source project webkit r105591scope: - version: -

Trust: 0.3

vendor:webkitmodel:open source project webkitscope:eqversion:2

Trust: 0.3

vendor:webkitmodel:open source project webkitscope:eqversion:1.2.2-1

Trust: 0.3

vendor:webkitmodel:open source project webkitscope:eqversion:0

Trust: 0.3

vendor:applemodel:itunesscope:eqversion:10.5.1

Trust: 0.3

vendor:applemodel:itunesscope:eqversion:10.6

Trust: 0.3

vendor:applemodel:itunesscope:eqversion:10.5

Trust: 0.3

vendor:applemodel:tvscope:eqversion:4.2

Trust: 0.3

vendor:applemodel:iphone ipodtouchscope:eqversion:4.0.1-

Trust: 0.3

vendor:applemodel:tvscope:eqversion:5.0

Trust: 0.3

vendor:applemodel:iphone ipodtouchscope:eqversion:3.1.2-

Trust: 0.3

vendor:applemodel:iphone ipodtouchscope:eqversion:3.1.3-

Trust: 0.3

vendor:applemodel:tvscope:eqversion:4.1

Trust: 0.3

vendor:applemodel:iphone iphonescope:eqversion:4.0.1-

Trust: 0.3

vendor:applemodel:iphone iphonescope:eqversion:3.1.2-

Trust: 0.3

vendor:applemodel:iphone iphonescope:eqversion:3.1.3-

Trust: 0.3

vendor:applemodel:iphone ipodtouchscope:eqversion:4.0-

Trust: 0.3

vendor:applemodel:iphone ipodtouchscope:eqversion:3.2-

Trust: 0.3

vendor:applemodel:iphone ipodtouchscope:eqversion:3.0.1-

Trust: 0.3

vendor:applemodel:ipod touchscope:eqversion:0

Trust: 0.3

vendor:applemodel:ipod touchscope:eqversion:3.1.3

Trust: 0.3

vendor:applemodel:tvscope:eqversion:4.4

Trust: 0.3

vendor:applemodel:iphone iphonescope:eqversion:4.0-

Trust: 0.3

vendor:applemodel:iphone iphonescope:eqversion:3.2-

Trust: 0.3

vendor:applemodel:iphone iphonescope:eqversion:3.0.1-

Trust: 0.3

vendor:applemodel:iphone ipodtouchscope:eqversion:3.0-

Trust: 0.3

vendor:applemodel:iphone ipodtouchscope:eqversion:3.1-

Trust: 0.3

vendor:applemodel:iphone iphonescope:eqversion:3.0-

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:0

Trust: 0.3

vendor:applemodel:iphone ipadscope:eqversion:3.2.1-

Trust: 0.3

vendor:applemodel:iphone iphonescope:eqversion:3.1-

Trust: 0.3

vendor:applemodel:ipadscope:eqversion:0

Trust: 0.3

vendor:applemodel:tvscope:eqversion:4.0

Trust: 0.3

vendor:applemodel:tvscope:eqversion:4.3

Trust: 0.3

sources: BID: 57587 // BID: 57572 // JVNDB: JVNDB-2013-001309 // CNNVD: CNNVD-201301-553 // NVD: CVE-2013-0955

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-0955
value: MEDIUM

Trust: 1.0

NVD: CVE-2013-0955
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201301-553
value: MEDIUM

Trust: 0.6

VULHUB: VHN-60957
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2013-0955
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-60957
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-60957 // JVNDB: JVNDB-2013-001309 // CNNVD: CNNVD-201301-553 // NVD: CVE-2013-0955

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.9

sources: VULHUB: VHN-60957 // JVNDB: JVNDB-2013-001309 // NVD: CVE-2013-0955

THREAT TYPE

network

Trust: 0.6

sources: BID: 57587 // BID: 57572

TYPE

Unknown

Trust: 0.6

sources: BID: 57587 // BID: 57572

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-001309

PATCH

title:APPLE-SA-2013-03-14-2url:http://lists.apple.com/archives/security-announce/2013/Mar/msg00003.html

Trust: 0.8

title:APPLE-SA-2013-05-16-1url:http://lists.apple.com/archives/security-announce/2013/May/msg00000.html

Trust: 0.8

title:APPLE-SA-2013-01-28-1url:http://lists.apple.com/archives/security-announce/2013/Jan/msg00000.html

Trust: 0.8

title:HT5671url:http://support.apple.com/kb/HT5671

Trust: 0.8

title:HT5766url:http://support.apple.com/kb/HT5766

Trust: 0.8

title:HT5642url:http://support.apple.com/kb/HT5642

Trust: 0.8

title:HT5671url:http://support.apple.com/kb/HT5671?viewlocale=ja_JP

Trust: 0.8

title:HT5766url:http://support.apple.com/kb/HT5766?viewlocale=ja_JP

Trust: 0.8

title:HT5642url:http://support.apple.com/kb/HT5642?viewlocale=ja_JP

Trust: 0.8

sources: JVNDB: JVNDB-2013-001309

EXTERNAL IDS

db:NVDid:CVE-2013-0955

Trust: 3.1

db:BIDid:57572

Trust: 0.9

db:JVNid:JVNVU95668478

Trust: 0.8

db:JVNid:JVNVU92876220

Trust: 0.8

db:JVNDBid:JVNDB-2013-001309

Trust: 0.8

db:CNNVDid:CNNVD-201301-553

Trust: 0.7

db:SECUNIAid:52002

Trust: 0.7

db:APPLEid:APPLE-SA-2013-01-28-1

Trust: 0.6

db:BIDid:57587

Trust: 0.4

db:VULHUBid:VHN-60957

Trust: 0.1

db:PACKETSTORMid:120821

Trust: 0.1

db:PACKETSTORMid:119897

Trust: 0.1

db:PACKETSTORMid:119887

Trust: 0.1

db:PACKETSTORMid:121672

Trust: 0.1

sources: VULHUB: VHN-60957 // BID: 57587 // BID: 57572 // JVNDB: JVNDB-2013-001309 // PACKETSTORM: 120821 // PACKETSTORM: 119897 // PACKETSTORM: 119887 // PACKETSTORM: 121672 // CNNVD: CNNVD-201301-553 // NVD: CVE-2013-0955

REFERENCES

url:http://support.apple.com/kb/ht5642

Trust: 1.8

url:http://lists.apple.com/archives/security-announce/2013/jan/msg00000.html

Trust: 1.7

url:http://lists.apple.com/archives/security-announce/2013/mar/msg00003.html

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-0955

Trust: 0.8

url:http://jvn.jp/cert/jvnvu95668478/

Trust: 0.8

url:http://jvn.jp/cert/jvnvu92876220/

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-0955

Trust: 0.8

url:http://www.apple.com/iphone/softwareupdate/

Trust: 0.6

url:http://www.apple.com/ipad/

Trust: 0.6

url:http://www.apple.com/iphone/

Trust: 0.6

url:http://www.apple.com/ipodtouch/

Trust: 0.6

url:http://secunia.com/advisories/52002

Trust: 0.6

url:http://www.securityfocus.com/bid/57572

Trust: 0.6

url:http://www.webkit.org/

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2013-0956

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2013-0954

Trust: 0.3

url:http://support.apple.com/kb/ht1222

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2013-0955

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2013-0948

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2013-0959

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2013-0952

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2013-0958

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2013-0949

Trust: 0.3

url:https://www.apple.com/support/security/pgp/

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2012-2857

Trust: 0.3

url:http://gpgtools.org

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2013-0950

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2013-0951

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2012-2824

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2013-0953

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2013-0961

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2013-0960

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2012-2889

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2013-0962

Trust: 0.2

url:https://www.apple.com/itunes/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3687

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3632

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3621

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3701

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0968

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-3058

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-2619

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0964

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0974

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3606

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3607

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0963

Trust: 0.1

url:https://ca.secunia.com/?page=viewadvisory&vuln_id=52002

Trust: 0.1

url:http://secunia.com/vulnerability_intelligence/

Trust: 0.1

url:http://secunia.com/advisories/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/personal/

Trust: 0.1

url:http://secunia.com/advisories/52002/#comments

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://secunia.com/blog/325/

Trust: 0.1

url:http://secunia.com/advisories/52002/

Trust: 0.1

url:http://secunia.com/advisories/about_secunia_advisories/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0997

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0912

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0996

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0879

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0992

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0995

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-1014

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0993

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3748

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0991

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0994

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0998

Trust: 0.1

url:http://www.apple.com/itunes/download/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-5112

Trust: 0.1

sources: VULHUB: VHN-60957 // BID: 57587 // BID: 57572 // JVNDB: JVNDB-2013-001309 // PACKETSTORM: 120821 // PACKETSTORM: 119897 // PACKETSTORM: 119887 // PACKETSTORM: 121672 // CNNVD: CNNVD-201301-553 // NVD: CVE-2013-0955

CREDITS

Mark Dowd of Azimuth Security, Andrew Plotkin of Zarfhome Software Consulting, Ben Madison of BitCloud, Marek Durcek, Abhishek Arya (Inferno) of the Google Chrome Security Team, Apple Product Security, Aaron Nelson, Mario Heiderich of Cure53

Trust: 0.9

sources: BID: 57572 // CNNVD: CNNVD-201301-553

SOURCES

db:VULHUBid:VHN-60957
db:BIDid:57587
db:BIDid:57572
db:JVNDBid:JVNDB-2013-001309
db:PACKETSTORMid:120821
db:PACKETSTORMid:119897
db:PACKETSTORMid:119887
db:PACKETSTORMid:121672
db:CNNVDid:CNNVD-201301-553
db:NVDid:CVE-2013-0955

LAST UPDATE DATE

2025-04-11T21:46:51.658000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-60957date:2013-03-16T00:00:00
db:BIDid:57587date:2013-05-16T20:23:00
db:BIDid:57572date:2013-01-29T12:40:00
db:JVNDBid:JVNDB-2013-001309date:2013-05-20T00:00:00
db:CNNVDid:CNNVD-201301-553date:2013-01-30T00:00:00
db:NVDid:CVE-2013-0955date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:VULHUBid:VHN-60957date:2013-01-29T00:00:00
db:BIDid:57587date:2013-01-28T00:00:00
db:BIDid:57572date:2013-01-28T00:00:00
db:JVNDBid:JVNDB-2013-001309date:2013-01-30T00:00:00
db:PACKETSTORMid:120821date:2013-03-15T22:28:44
db:PACKETSTORMid:119897date:2013-01-30T02:53:29
db:PACKETSTORMid:119887date:2013-01-29T06:19:58
db:PACKETSTORMid:121672date:2013-05-17T13:33:33
db:CNNVDid:CNNVD-201301-553date:2013-01-30T00:00:00
db:NVDid:CVE-2013-0955date:2013-01-29T05:58:54.663