Apple iOS < 6.1.3 Multiple Vulnerabilities

High Nessus Plugin ID 65633

Synopsis

Report iOS devices older than 6.1.3.

Description

The mobile device is running a version of iOS that is older than version 6.1.3. This version contains security-related fixes for the following issues :

- A state management error exists related to 'Mach-O' files and overlapping segments that could allow execution of unsigned code. (CVE-2013-0977)

- An error exists related to the ARM prefetch abort handler that could allow disclosure of sensitive information. (CVE-2013-0978)

- An error exists related to 'lockdownd' and file permissions restrictions. (CVE-2013-0979)

- An error exists related to screen locking that could allow unauthorized access. (CVE-2013-0980)

- An error exists related to IOUSBDeviceFamily driver used pipe object pointers that could allow execution of arbitrary code. (CVE-2013-0981)

- A variable casting error exists related to the bundled 'WebKit' component and SVG handling. (CVE-2013-0912)

Solution

Apple has released a set of patches for iOS-based devices.

See Also

https://support.apple.com/en-us/HT202706

https://lists.apple.com/archives/security-announce/2013/Mar/msg00004.html

Plugin Details

Severity: High

ID: 65633

File Name: apple_ios_613_check.nbin

Version: 1.62

Type: local

Published: 2013/03/20

Updated: 2019/11/27

Dependencies: 60033

Risk Information

Risk Factor: High

CVSS Score Source: CVE-2013-0912

CVSS v2.0

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/o:apple:iphone_os

Required KB Items: mdm/dependency/unlocked

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2013/03/19

Vulnerability Publication Date: 2013/02/15

Reference Information

CVE: CVE-2013-0912, CVE-2013-0977, CVE-2013-0978, CVE-2013-0979, CVE-2013-0980, CVE-2013-0981

BID: 57967, 57990, 58586, 58588, 58589, 58590