← Back

CVE-2013-3949

nvd nist
Published: Jun 5, 2013Modified: Apr 29, 2026

JSON object

Loading...
2.1
Vector
AV:L/AC:L/Au:N/C:N/I:P/A:N
Exploitability: 3.9 / Impact: 2.9
Source: NVD

Description

The posix_spawn system call in the XNU kernel in Apple Mac OS X 10.8.x does not prevent use of the _POSIX_SPAWN_DISABLE_ASLR and _POSIX_SPAWN_ALLOW_DATA_EXEC flags for setuid and setgid programs, which allows local users to bypass intended access restrictions via a wrapper program that calls the posix_spawnattr_setflags function.

Affected (5)

Products: Apple: Mac Os X
1 product
Mac Os X
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Version 10.8.0
Version 10.8.1
Version 10.8.2
Version 10.8.3
Version 10.8.4

Related CWEs

Timeline

No history available yet.