2 results (0.010 seconds)

CVSS: 5.3EPSS: 0%CPEs: 7EXPL: 0

The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket. La función socket_create en common/socket.c en libimobiledevice y libusbmuxd permite a atacantes remotos eludir las restricciones destinadas al acceso y comunicarse con servicios en dispositivos de iOS conectándose a un socket IPv4 TCP. • http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00042.html http://lists.opensuse.org/opensuse-updates/2016-06/msg00029.html http://www.openwall.com/lists/oss-security/2016/05/26/1 http://www.openwall.com/lists/oss-security/2016/05/26/6 http://www.ubuntu.com/usn/USN-3026-1 http://www.ubuntu.com/usn/USN-3026-2 https://bugzilla.redhat.com/show_bug.cgi?id=1339988 https://github.com/libimobiledevice/libimobiledevice/commit/df1f5c4d70d0c19ad40072f5246ca457e7f9849e https: • CWE-284: Improper Access Control •

CVSS: 3.3EPSS: 0%CPEs: 1EXPL: 1

userpref.c in libimobiledevice 1.1.4, when $HOME and $XDG_CONFIG_HOME are not set, allows local users to overwrite arbitrary files via a symlink attack on (1) HostCertificate.pem, (2) HostPrivateKey.pem, (3) libimobiledevicerc, (4) RootCertificate.pem, or (5) RootPrivateKey.pem in /tmp/root/.config/libimobiledevice/. userpref.c en libimobiledevice 1.1.4, cuando $HOME y $XDG_CONFIG_HOME no están definidos, permite a usuarios locales sobreescribir archivos d eforma arbitraria a través de un ataque symlink en (1) HostCertificate.pem, (2)HostPrivateKey.pem, (3) libimobiledevicerc, (4) RootCertificate.pem, o (5) RootPrivateKey.pem en /tmp/root/.config/libimobiledevice/. • http://libiphone.lighthouseapp.com/projects/27916-libiphone/tickets/331-insecure-tmp-directory-use http://www.openwall.com/lists/oss-security/2013/06/04/11 http://www.ubuntu.com/usn/USN-1927-1 https://bugs.launchpad.net/ubuntu/%2Bsource/libimobiledevice/%2Bbug/1164263 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •