Permissions, Privileges, and Access Controls in macOS - CVE-2013-3952
Published: June 5, 2013 / Updated: August 11, 2020
macOS
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to manipulate data.
The fill_pipeinfo function in bsd/kern/sys_pipe.c in the XNU kernel in Apple Mac OS X 10.8.x allows local users to defeat the KASLR protection mechanism via the PROC_PIDFDPIPEINFO option to the proc_info system call for a kernel pipe handle.