CVE-2013-3955
Estado: ModificadaMedia (6.2)—
The get_xattrinfo function in the XNU kernel in Apple iOS 5.x and 6.x through 6.1.3 on iPad devices does not properly validate the header of an AppleDouble file, which might allow local users to cause a denial of service (memory corruption) or have unspecified other impact via an invalid file on an msdosfs filesystem.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C
- Puntuación base: 6.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.42%
- Percentil entre todas las CVEs puntuadas: 34
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (4)
CWE
- CWE-20
Referencias
- http://antid0te.com/syscan_2013/SyScan2013_Mountain_Lion_iOS_Vulnerabilities_Garage_Sale_Whitepaper.pdf
- http://lists.apple.com/archives/security-announce/2013/Sep/msg00006.html
- http://support.apple.com/kb/HT5934
- http://www.securitytracker.com/id/1029054
- http://www.syscan.org/index.php/sg/program/day/2
- http://antid0te.com/syscan_2013/SyScan2013_Mountain_Lion_iOS_Vulnerabilities_Garage_Sale_Whitepaper.pdf
- http://lists.apple.com/archives/security-announce/2013/Sep/msg00006.html
- http://support.apple.com/kb/HT5934
- http://www.securitytracker.com/id/1029054
- http://www.syscan.org/index.php/sg/program/day/2
JSON original (NVD)
Mostrar
{
"id": "CVE-2013-3955",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:H/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "HIGH",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 1.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2013-06-05T14:39:57.877",
"references": [
{
"url": "http://antid0te.com/syscan_2013/SyScan2013_Mountain_Lion_iOS_Vulnerabilities_Garage_Sale_Whitepaper.pdf",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://lists.apple.com/archives/security-announce/2013/Sep/msg00006.html",
"source": "cve@mitre.org"
},
{
"url": "http://support.apple.com/kb/HT5934",
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id/1029054",
"source": "cve@mitre.org"
},
{
"url": "http://www.syscan.org/index.php/sg/program/day/2",
"source": "cve@mitre.org"
},
{
"url": "http://antid0te.com/syscan_2013/SyScan2013_Mountain_Lion_iOS_Vulnerabilities_Garage_Sale_Whitepaper.pdf",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.apple.com/archives/security-announce/2013/Sep/msg00006.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://support.apple.com/kb/HT5934",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1029054",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.syscan.org/index.php/sg/program/day/2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The get_xattrinfo function in the XNU kernel in Apple iOS 5.x and 6.x through 6.1.3 on iPad devices does not properly validate the header of an AppleDouble file, which might allow local users to cause a denial of service (memory corruption) or have unspecified other impact via an invalid file on an msdosfs filesystem."
},
{
"lang": "es",
"value": "La función get_xattrinfo en el XNU kernel en Apple iOS v5.x y v6.x hasta 6.1.3 en dispositivos iPad no valida correctamente el encabezado de un fichero AppleDouble, lo que podría permitir a usuarios locales provocar una denegación de servicio (corrupción de memoria) o tienen un impacto no especificado a través de un archivo no válido en un sistema de ficheros msdosfs."
}
],
"lastModified": "2026-06-16T23:56:05.203",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:apple:iphone_os:5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "06980521-B0EA-434D-89AD-A951EAF1D23F"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:5.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A3AE6A93-3977-4B32-B2F6-55C94387DDE3"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:5.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E78F1F2C-2BFF-4D55-A754-102D6C42081B"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:5.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A0A4AF71-8E71-432A-B908-361DAF99F4B9"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DEE0068D-C699-4646-9658-610409925A79"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:6.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "87C215DD-BC98-4283-BF13-69556EF7CB78"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:6.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C1C3966E-C136-47A9-B5B4-70613756ED27"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:6.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "22AD2A1F-A637-47DE-A69F-DAE4ABDFA4BD"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:6.1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F6D398B8-821B-4DE9-ADF1-4983051F964C"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:6.1.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E0CCE5F2-4D32-404B-BAAC-E64F11BD41FB"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:apple:ipad:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BAADE29A-712B-4AD5-A78B-6AD537BA9196"
},
{
"criteria": "cpe:2.3:h:apple:ipad_mini:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9BB7BAFA-DEB1-48EA-B11C-1FF0E9019A51"
},
{
"criteria": "cpe:2.3:h:apple:ipad2:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E7BFD4E0-321E-4ECB-82A5-80E9CB6E4EED"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}