Apple TV Multiple Vulnerabilities
Last Update Date:
30 Nov 2012 10:46
Release Date:
30 Nov 2012
4562
Views
RISK: Medium Risk
TYPE: Clients - Audio & Video
Multiple vulnerabilities have been identified in Apple TV, which can be exploit by malicious user to execute arbitrary code, access privilaged data and cause denial of service.
- An information disclosure issue existed in the handling of APIs related to kernel extensions. Responses containing a OSBundleMachOHeaders key may have included kernel addresses, which may aid in bypassing address space layout randomization protection.
- An attacker with a privileged network position may cause an unexpected application termination or arbitrary code execution. A time of check to time of use issue existed in the handling of JavaScript arrays.
Impact
- Denial of Service
- Remote Code Execution
- Information Disclosure
System / Technologies affected
- Apple TV version prior to 5.1.1.
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to Apple TV version 5.1.1.
Vulnerability Identifier
Source
Related Link
Share with