vendor:
Flow Divert
by:
Brandon Azad
7,8
CVSS
HIGH
Heap Overflow
119
CWE
Product Name: Flow Divert
Affected Version From: OS X Yosemite
Affected Version To: OS X El Capitan 10.11.5 and iOS 9.3.2.
Patch Exists: YES
Related CWE: CVE-2016-1827
CPE: OS X and iOS
Metasploit:
https://www.rapid7.com/db/vulnerabilities/apple-osx-kernel-cve-2016-1827/, https://www.rapid7.com/db/vulnerabilities/apple-osx-kernel-cve-2016-1828/, https://www.rapid7.com/db/vulnerabilities/apple-osx-kernel-cve-2016-1829/, https://www.rapid7.com/db/vulnerabilities/apple-osx-kernel-cve-2016-1830/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: OS X Yosemite
2016
Kernel Heap Overflow in the function flow_divert_handle_app_map_create on OS X and iOS
This proof-of-concept triggers a kernel panic on OS X Yosemite. In El Capitan the length fields were changed from 64 bits to 32 bits, so the message structure will need to be updated accordingly. This exploit has not been tested on iOS.
Mitigation:
The vulnerability was patched in OS X El Capitan 10.11.5 and iOS 9.3.2.