Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2013-3949

The posix_spawn system call in the XNU kernel in Apple Mac OS X 10.8.x does not prevent use of the _POSIX_SPAWN_DISABLE_ASLR and _POSIX_SPAWN_ALLOW_DATA_EXEC flags for setuid and setgid programs, which allows local users to bypass intended access restrictions via a wrapper program that calls the posix_spawnattr_setflags function.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 14.5%
CVSS Severity
CVSS v2 Score 2.1
Products affected by CVE-2013-3949
  • Apple » Mac Os X » Version: 10.8.0
    cpe:2.3:o:apple:mac_os_x:10.8.0
  • Apple » Mac Os X » Version: 10.8.1
    cpe:2.3:o:apple:mac_os_x:10.8.1
  • Apple » Mac Os X » Version: 10.8.2
    cpe:2.3:o:apple:mac_os_x:10.8.2
  • Apple » Mac Os X » Version: 10.8.3
    cpe:2.3:o:apple:mac_os_x:10.8.3
  • Apple » Mac Os X » Version: 10.8.4
    cpe:2.3:o:apple:mac_os_x:10.8.4


Contact Us

Shodan ® - All rights reserved