CVE detail
CVE-2013-3951 — CVE-2013-3951
Published 2013-06-05 · Modified 2026-06-16 · Vendor apple · Product iphone_os · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0046
EPSS probability
exploitation probability, 30d
37.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
sys/openbsd/stack_protector.c in libc in Apple iOS 6.1.3 and Mac OS X 10.8.x does not properly parse the Apple strings employed in the user-space stack-cookie implementation, which allows local users to bypass cookie randomization by executing a program with a call-path beginning with the stack-guard= substring, as demonstrated by an iOS untethering attack or an attack against a setuid Mac OS X program.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References