Vulnerability CVE-2016-5104


Published: 2016-06-13

Description:
The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket.

Type:

CWE-284

(Improper Access Control)

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
Opensuse -> LEAP 
Opensuse -> Opensuse 
Novell -> LEAP 
Novell -> Opensuse 
Libimobiledevice -> Libimobiledevice 
Libimobiledevice -> Libusbmuxd 
Canonical -> Ubuntu linux 

 References:
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00042.html
http://lists.opensuse.org/opensuse-updates/2016-06/msg00029.html
http://www.openwall.com/lists/oss-security/2016/05/26/1
http://www.openwall.com/lists/oss-security/2016/05/26/6
http://www.ubuntu.com/usn/USN-3026-1
http://www.ubuntu.com/usn/USN-3026-2
https://bugzilla.redhat.com/show_bug.cgi?id=1339988
https://github.com/libimobiledevice/libimobiledevice/commit/df1f5c4d70d0c19ad40072f5246ca457e7f9849e
https://github.com/libimobiledevice/libusbmuxd/commit/4397b3376dc4e4cb1c991d0aed61ce6482614196

Copyright 2024, cxsecurity.com

 

Back to Top