3.3
CVSSv2

CVE-2013-2142

Published: 19/01/2014 Updated: 21/01/2014
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
VMScore: 294
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

userpref.c in libimobiledevice 1.1.4, when $HOME and $XDG_CONFIG_HOME are not set, allows local users to overwrite arbitrary files via a symlink attack on (1) HostCertificate.pem, (2) HostPrivateKey.pem, (3) libimobiledevicerc, (4) RootCertificate.pem, or (5) RootPrivateKey.pem in /tmp/root/.config/libimobiledevice/.

Vulnerable Product Search on Vulmon Subscribe to Product

libimobiledevice libimobiledevice 1.1.4

Vendor Advisories

Debian Bug report logs - #710885 libimobiledevice: CVE-2013-2142: insecure /tmp usage Package: libimobiledevice; Maintainer for libimobiledevice is gtkpod Maintainers <pkg-gtkpod-devel@alioth-listsdebiannet>; Reported by: Henri Salo <henri@nervfi> Date: Mon, 3 Jun 2013 09:37:13 UTC Severity: important Tags: secur ...
libimobiledevice could be made to overwrite files as the administrator, or access device keys ...
userprefc in libimobiledevice 114, when $HOME and $XDG_CONFIG_HOME are not set, allows local users to overwrite arbitrary files via a symlink attack on (1) HostCertificatepem, (2) HostPrivateKeypem, (3) libimobiledevicerc, (4) RootCertificatepem, or (5) RootPrivateKeypem in /tmp/root/config/libimobiledevice/ ...