René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

145 lines
4.9 KiB
JSON

{
"id": "CVE-2014-1372",
"sourceIdentifier": "product-security@apple.com",
"published": "2014-07-01T10:17:27.220",
"lastModified": "2015-11-20T16:10:19.243",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "Graphics Driver in Apple OS X before 10.9.4 does not properly restrict read operations during processing of an unspecified system call, which allows local users to obtain sensitive information from kernel memory and bypass the ASLR protection mechanism via a crafted call."
},
{
"lang": "es",
"value": "Graphics Driver en Apple OS X anterior a 10.9.4 no restringe debidamente operaciones de lectura durante el procesamiento de una llamada del sistema no especificada, lo que permite a usuarios locales obtener informaci\u00f3n sensible de la memoria del kernel y evadir el mecanismo de protecci\u00f3n ASLR a trav\u00e9s de una llamada manipulada."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:N/A:N",
"accessVector": "LOCAL",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 4.9
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 3.9,
"impactScore": 6.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*",
"versionEndIncluding": "10.9.3",
"matchCriteriaId": "8EB864BA-7FED-47E3-9391-B89598594AF8"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:apple:mac_os_x:10.8.0:*:*:*:*:*:*:*",
"matchCriteriaId": "B2082D62-3821-4DBA-8690-67489F44C38D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:apple:mac_os_x:10.8.1:*:*:*:*:*:*:*",
"matchCriteriaId": "8F0DB1BC-DC16-423E-B0C7-8E9C996A50B5"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:apple:mac_os_x:10.8.2:*:*:*:*:*:*:*",
"matchCriteriaId": "E59315BA-B9F1-46A5-86E7-8BE2ED97BA4F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:apple:mac_os_x:10.8.3:*:*:*:*:*:*:*",
"matchCriteriaId": "55841123-F78F-42E0-8D40-C688C4B4D29C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:apple:mac_os_x:10.8.4:*:*:*:*:*:*:*",
"matchCriteriaId": "252640D3-5CB8-4C3D-9E8B-ED452293C805"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:apple:mac_os_x:10.8.5:*:*:*:*:*:*:*",
"matchCriteriaId": "F3D30B4B-DA63-40B0-B0C9-F3992CF25706"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:apple:mac_os_x:10.8.5:supplemental_update:*:*:*:*:*:*",
"matchCriteriaId": "2F1DAD30-BA77-40C2-9245-05DF871FDDC0"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:apple:mac_os_x:10.9:*:*:*:*:*:*:*",
"matchCriteriaId": "A48A5310-A589-4E9B-99BC-F840CC1A6A44"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:apple:mac_os_x:10.9.1:*:*:*:*:*:*:*",
"matchCriteriaId": "F241EBFB-CCB3-4D16-B476-AC1578D3C435"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:apple:mac_os_x:10.9.2:*:*:*:*:*:*:*",
"matchCriteriaId": "7AEAD650-87D1-49BB-A8C7-BA39FD47285C"
}
]
}
]
}
],
"references": [
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2014-06/0172.html",
"source": "product-security@apple.com"
},
{
"url": "http://support.apple.com/kb/HT6296",
"source": "product-security@apple.com"
},
{
"url": "http://www.securitytracker.com/id/1030505",
"source": "product-security@apple.com"
},
{
"url": "https://code.google.com/p/google-security-research/issues/detail?id=18",
"source": "product-security@apple.com",
"tags": [
"Exploit"
]
}
]
}