CVE-2013-5133
published 2014-03-14CVE-2013-5133: Backup in Apple iOS before 7.1 does not properly restrict symlinks, which allows remote attackers to overwrite files during a restore operation via crafted…
PriorityP342high8.8CVSS 2.0
AVNACMAuNCNICAC
EPSS
1.74%
75.5th percentile
Backup in Apple iOS before 7.1 does not properly restrict symlinks, which allows remote attackers to overwrite files during a restore operation via crafted backup data.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | <= 7.0.6 | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apple iOS 6.1/7.0.5 autoload.lib access control (HT6162 / XFDB-91710)
vuldb·2026-05-08·CVSS 8.8
CVE-2013-5133 [HIGH] Apple iOS 6.1/7.0.5 autoload.lib access control (HT6162 / XFDB-91710)
A vulnerability was found in Apple iOS 6.1/7.0.5 and classified as problematic. Affected by this vulnerability is an unknown functionality in the library autoload.lib. Executing a manipulation can lead to improper access controls.
This vulnerability is tracked as CVE-2013-5133. The attack is restricted to local execution. Moreover, an exploit is present.
A patch should be applied to remediate this issue.
GHSA
GHSA-6hmq-v65x-pjjh: Backup in Apple iOS before 7
ghsa_unreviewed·2022-05-17
CVE-2013-5133 [HIGH] GHSA-6hmq-v65x-pjjh: Backup in Apple iOS before 7
Backup in Apple iOS before 7.1 does not properly restrict symlinks, which allows remote attackers to overwrite files during a restore operation via crafted backup data.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-03-14
Published