OSVDB ID: 85629

Title: Apple iOS Kernel Packet Filter IOTCL Parsing Invalid Pointer Dereference Local Privilege Escalation

Info

Disclosure

Sep 19, 2012

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Sep 19, 2012

Description

Apple iOS contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when an error occurs in the kernel during the handling of packet filter IOCTLs. This may allow a local attacker to dereference an invalid pointer. With a specially crafted program that makes packet-filter ioctl calls, a local attacker can gain escalated privileges.

Classification

Location: Local Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Upgrade
Exploit: Exploit Private
Disclosure: Vendor Verified, Coordinated Disclosure
OSVDB: Authentication Required

Solution

Upgrade to version 6 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Apple Inc.

Apple iOS

5.1.1

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/85629