vendor:
Mac OS X
by:
@rpaleari and @joystick
7.8
CVSS
HIGH
Stack Canary Overwrite
119
CWE
Product Name: Mac OS X
Affected Version From: Mac OS X Yosemite (10.10)
Affected Version To: Mac OS X Yosemite (10.10)
Patch Exists: NO
Related CWE: N/A
CPE: o:apple:mac_os_x
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Mac OS X
2015
IOBluetoothHCIUserClient Stack Canary Overwrite
This exploit triggers a panic by overwriting a stack_canary. It does this by calling IOBluetoothHCIUserClient::DispatchHCIReadLocalName() with an argument that overflows a local buffer and the adjacent stack canary.
Mitigation:
Ensure that stack canaries are properly implemented and that all user input is properly validated.