vendor:
Mac OS X
by:
Ian Beer
7,2
CVSS
HIGH
NULL dereference
476
CWE
Product Name: Mac OS X
Affected Version From: OS X 10.11.4 (15E65)
Affected Version To: OS X 10.11.4 (15E65)
Patch Exists: NO
Related CWE: N/A
CPE: o:apple:mac_os_x:10.11.4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: OS X 10.11.4 (15E65)
2016
OS X exploitable kernel NULL dereference in CoreCaptureResponder due to unchecked return value
Pretty much all the external methods of CoreCaptureUserClient call CoreCaptureUserClient::stashGet passing an attacker controlled key. If that key isn't in the list of stashed objects then stashGet returns a NULL pointer. No callers actually check the return value though which leads immediately to a call to a virtual method on a NULL pointer. By mapping the NULL page we can get trivial RIP control.
Mitigation:
Check the return value of CoreCaptureUserClient::stashGet before calling a virtual method on it.