CVE-2011-3442

iPhone OS - Arbitrary Unsigned Code Execution via mmap Flag Validation Bypass

Title source: llm
STIX 2.1

Description

The kernel in Apple iOS before 5.0.1 does not ensure the validity of flag combinations for an mmap system call, which allows local users to execute arbitrary unsigned code via a crafted app.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1026287
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/Security-announce/2011/Nov/msg00001.html
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT5052

Scores

EPSS 0.0036
EPSS Percentile 28.2%

Details

CWE
CWE-399
Status published
Products (7)
apple/iphone_os 4.3.0
apple/iphone_os 4.3.1
apple/iphone_os 4.3.2
apple/iphone_os 4.3.3
apple/iphone_os 4.3.4
apple/iphone_os 4.3.5 (3 CPE variants)
apple/iphone_os 5.0 (4 CPE variants)
Published Nov 11, 2011
Tracked Since Feb 18, 2026