CVE-2013-3949
Mac OS X 10.8.x - Local Privilege Escalation via posix_spawn ASLR Bypass
Title source: llmDescription
The posix_spawn system call in the XNU kernel in Apple Mac OS X 10.8.x does not prevent use of the _POSIX_SPAWN_DISABLE_ASLR and _POSIX_SPAWN_ALLOW_DATA_EXEC flags for setuid and setgid programs, which allows local users to bypass intended access restrictions via a wrapper program that calls the posix_spawnattr_setflags function.
References (2)
Core 2
Core References
Various Sources x_refsource_misc
http://www.syscan.org/index.php/sg/program/day/2
Scores
EPSS
0.0049
EPSS Percentile
39.5%
Details
CWE
CWE-264
Status
published
Products (5)
apple/mac_os_x
10.8.0
apple/mac_os_x
10.8.1
apple/mac_os_x
10.8.2
apple/mac_os_x
10.8.3
apple/mac_os_x
10.8.4
Published
Jun 05, 2013
Tracked Since
Feb 18, 2026