Back to search
CVE-2013-2142
Published: Jan 19, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
userpref.c in libimobiledevice 1.1.4, when $HOME and $XDG_CONFIG_HOME are not set, allows local users to overwrite arbitrary files via a symlink attack on (1) HostCertificate.pem, (2) HostPrivateKey.pem, (3) libimobiledevicerc, (4) RootCertificate.pem, or (5) RootPrivateKey.pem in /tmp/root/.config/libimobiledevice/.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20130604 Re: CVE Request: libimobiledevice insecure /tmp use
mailing-list
x_refsource_MLIST
https://bugs.launchpad.net/ubuntu/%2Bsource/libimobiledevice/%2Bbug/1164263
x_refsource_CONFIRM
USN-1927-1
vendor-advisory
x_refsource_UBUNTU
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now