[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-2142Date: (C)2014-01-21   (M)2023-12-22


userpref.c in libimobiledevice 1.1.4, when $HOME and $XDG_CONFIG_HOME are not set, allows local users to overwrite arbitrary files via a symlink attack on (1) HostCertificate.pem, (2) HostPrivateKey.pem, (3) libimobiledevicerc, (4) RootCertificate.pem, or (5) RootPrivateKey.pem in /tmp/root/.config/libimobiledevice/.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 3.3
Exploit Score: 3.4
Impact Score: 4.9
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
USN-1927-1
http://www.openwall.com/lists/oss-security/2013/06/04/11
http://libiphone.lighthouseapp.com/projects/27916-libiphone/tickets/331-insecure-tmp-directory-use
https://bugs.launchpad.net/ubuntu/%2Bsource/libimobiledevice/%2Bbug/1164263

CPE    1
cpe:/a:libimobiledevice:libimobiledevice:1.1.4
CWE    1
CWE-59
OVAL    9
oval:org.secpod.oval:def:107421
oval:org.secpod.oval:def:107399
oval:org.secpod.oval:def:107423
oval:org.secpod.oval:def:107404
...

© SecPod Technologies