Apple iPhone/iPad/iPod touch Prior to iOS 6.1.3 CVE-2013-0979 Local Security Bypass Vulnerability
BID:58588
Info
Apple iPhone/iPad/iPod touch Prior to iOS 6.1.3 CVE-2013-0979 Local Security Bypass Vulnerability
| Bugtraq ID: | 58588 |
| Class: | Design Error |
| CVE: |
CVE-2013-0979 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 19 2013 12:00AM |
| Updated: | Mar 19 2013 12:00AM |
| Credit: | evad3rs |
| Vulnerable: |
Apple iPod Touch 3.1.3 Apple iPod Touch 3.1.2 Apple iPod Touch 3.1.1 Apple iPod Touch 3.0 Apple iPhone 4.0.1 Apple iPhone 3.2.1 Apple iPhone 3.1.3 Apple iPhone 3.1.2 Apple iPhone 3.0.1 Apple iPhone 4.3.3 Apple iPhone 4.3.2 Apple iPhone 4.3.1 Apple iPhone 4.3.0 Apple iPhone 4.2.8 Apple iPhone 4.2.5 Apple iPhone 4.2.1 Apple iPhone 4.1 Apple iPhone 4.0.2 Apple iPhone 4.0 Apple iPhone 3.2.2 Apple iPhone 3.2 Apple iPhone 3.1 Apple iPhone 3.0 Apple iPad 3.2.1 Apple iPad 3.2.2 Apple iPad 3.2 Apple iOS 4.2.1 Apple iOS 4.0.2 Apple iOS 4.0.1 Apple iOS 3.2.2 Apple iOS 3.2.1 Apple iOS 5.1.1 Apple iOS 5.1 Apple iOS 5.0.1 Apple iOS 5 Apple iOS 4.3.5 Apple iOS 4.3.4 Apple iOS 4.3.3 Apple iOS 4.3.2 Apple iOS 4.3.1 Apple iOS 4.3 Apple iOS 4.2.9 Apple iOS 4.2.8 Apple iOS 4.2.7 Apple iOS 4.2.6 Apple iOS 4.2.5 Apple iOS 4.2.10 Apple iOS 4.2 Apple iOS 4.1 Apple iOS 4 Apple iOS 3.2 Apple iOS 3.1 Apple iOS 3.0 Apple iOS 2.1 Apple iOS 2.0 |
| Not Vulnerable: | |
Discussion
Apple iPhone/iPad/iPod touch Prior to iOS 6.1.3 CVE-2013-0979 Local Security Bypass Vulnerability
Apple iOS for the iPhone, the iPod touch, and the iPad is prone to a local security-bypass vulnerability.
An attacker with physical access to the affected device can exploit this issue to change permissions on arbitrary files.
Apple iOS for the iPhone, the iPod touch, and the iPad is prone to a local security-bypass vulnerability.
An attacker with physical access to the affected device can exploit this issue to change permissions on arbitrary files.
Exploit / POC
Apple iPhone/iPad/iPod touch Prior to iOS 6.1.3 CVE-2013-0979 Local Security Bypass Vulnerability
An attacker requires physical access to exploit the issue.
An attacker requires physical access to exploit the issue.
Solution / Fix
Apple iPhone/iPad/iPod touch Prior to iOS 6.1.3 CVE-2013-0979 Local Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apple iPhone/iPad/iPod touch Prior to iOS 6.1.3 CVE-2013-0979 Local Security Bypass Vulnerability
References:
References:
- Apple iOS Homepage (Apple)
- iPad Homepage (Apple)
- iPhone Homepage (Apple)
- iPod touch Product Page (Apple)
- APPLE-SA-2013-03-19-1 iOS 6.1.3 (Apple)