Skip to main content

Apple TV Multiple Vulnerabilities

Last Update Date: 30 Nov 2012 10:46 Release Date: 30 Nov 2012 4562 Views

RISK: Medium Risk

TYPE: Clients - Audio & Video

TYPE: Audio & Video

Multiple vulnerabilities have been identified in Apple TV, which can be exploit by malicious user to execute arbitrary code, access privilaged data and cause denial of service.

  1. An information disclosure issue existed in the handling of APIs related to kernel extensions. Responses containing a OSBundleMachOHeaders key may have included kernel addresses, which may aid in bypassing address space layout randomization protection.
  2. An attacker with a privileged network position may cause an unexpected application termination or arbitrary code execution. A time of check to time of use issue existed in the handling of JavaScript arrays.

Impact

  • Denial of Service
  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

  • Apple TV version prior to 5.1.1.

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to Apple TV version 5.1.1.

Vulnerability Identifier


Source


Related Link