|
|
| |
|
| |
usbmuxd: code execution
| Package(s): | usbmuxd |
CVE #(s): | CVE-2012-0065
|
| Created: | February 1, 2012 |
Updated: | April 11, 2013 |
| Description: |
It turns out that usbmuxd does not perform proper bounds checking when processing the SerialNumber field provided by USB devices. A local attacker with a suitably modified USB device could exploit this failure to run arbitrary code as the "usbmux" user. |
| Alerts: |
|
( Log in to post comments)
|
|
|