Denial of Service Vulnerability in iOS 5.x and 6.x on Apple iPad
CVE-2013-3955
Currently unrated
Summary
The vulnerability exists in the get_xattrinfo function within the XNU kernel on Apple iOS versions 5.x and 6.x up to 6.1.3. It fails to adequately validate the headers of AppleDouble files, which could be exploited by local users to trigger a denial of service, potentially causing memory corruption or other unspecified impacts when interacting with an msdosfs filesystem. This flaw poses risks to the stability and security of affected devices.
References
Timeline
Vulnerability published
Vulnerability Reserved