Subscribe via feed.
Archive for February, 2020

macOS/iOS XNU mk_timer_create_trap() Race Condition

Posted by deepcore under exploit (No Respond)

macOS and iOS suffer from a race condition in XNU’s mk_timer_create_trap() that can lead to type confusion.

XNU OUserClient::_sendAsyncResult64() ipc_port Pointer Disclosure

Posted by deepcore under exploit (No Respond)

The XNU function IOUserClient::_sendAsyncResult64() discloses the address of the ipc_port to which the notification is sent in the Mach message enqueued on the notification port.

systemd-machined Incorrect Reference Decrement

Posted by deepcore under exploit (No Respond)

systemd has an issue in systemd-machined where it decrements the reference count when references are still held.

macOS/iOS ImageIO PVR Image Processing Heap Corruption

Posted by deepcore under exploit (No Respond)

macOS and iOS have an ImageIO heap corruption issue when processing malformed PVR images.

macOS/iOS ImageIO PVR Processing Out-Of-Bounds Read

Posted by deepcore under exploit (No Respond)

macOS and iOS suffer from an ImageIO out-of-bounds read when processing PVR images.

macOS/iOS IOAccelCommandQueue2::processSegmentKernelCommand() Out-Of-Bounds Timestamp Write

Posted by deepcore under exploit (No Respond)

macOS and iOS suffers from an out-of-bounds timestamp write in IOAccelCommandQueue2::processSegmentKernelCommand().

usersctp sctp_load_addresses_from_init Out-Of-Bounds Read

Posted by deepcore under exploit (No Respond)

usersctp is SCTP library used by a variety of software including WebRTC. There is a vulnerability in the sctp_load_addresses_from_init function of usersctp that can lead to a number of out-of-bound reads. The input to sctp_load_addresses_from_init is verified by calling sctp_arethere_unrecognized_parameters, however there is a difference in how these functions handle parameter bounds. The function sctp_arethere_unrecognized_parameters […]

ELAN Smart-Pad 11.10.15.1 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

ELAN Smart-Pad version 11.10.15.1 suffers from an unquoted service path vulnerability.

VIM 8.2 Denial Of Service

Posted by deepcore under exploit (No Respond)

VIM version 8.2 suffers from a denial of service vulnerability.

AbsoluteTelnet 11.12 Denial Of Service

Posted by deepcore under exploit (No Respond)

AbsoluteTelnet version 11.12 suffers from multiple denial of service vulnerabilities.