5
CVSSv2

CVE-2016-5104

Published: 13/06/2016 Updated: 30/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote malicious users to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket.

Vulnerable Product Search on Vulmon Subscribe to Product

libimobiledevice libusbmuxd

libimobiledevice libimobiledevice

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

canonical ubuntu linux 15.10

opensuse opensuse 13.2

opensuse leap 42.1

Vendor Advisories

Debian Bug report logs - #825553 libimobiledevice: CVE-2016-5104: Sockets listening on INADDR_ANY Package: src:libimobiledevice; Maintainer for src:libimobiledevice is gtkpod Maintainers <pkg-gtkpod-devel@alioth-listsdebiannet>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 27 May 2016 18:33:02 UT ...
libusbmuxd would allow unintended access to devices over the network ...
libimobiledevice would allow unintended access to devices over the network ...
The socket_create function in common/socketc in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket ...
The socket_create function in common/socketc in libimobiledevice and libusbmuxd allows remote attackers on the local network to bypass intended access restrictions and communicate with services on affected devices by connecting to an IPv4 TCP socket ...