CVE-2016-5104
published 2016-06-13CVE-2016-5104: The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate…
PriorityP433medium5.3CVSS 3.0
AVNACLPRNUINSUCNILAN
EPSS
2.99%
85.8th percentile
The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | libimobiledevice | < libimobiledevice 1.2.0+dfsg-3 (bookworm) | libimobiledevice 1.2.0+dfsg-3 (bookworm) |
| debian | libusbmuxd | < libimobiledevice 1.2.0+dfsg-3 (bookworm) | libimobiledevice 1.2.0+dfsg-3 (bookworm) |
| libimobiledevice | libimobiledevice | <= 1.2.0 | — |
| libimobiledevice | libimobiledevice | >= 0 < 1.2.0+dfsg-3 | 1.2.0+dfsg-3 |
| libimobiledevice | libimobiledevice | >= 0 < 1.2.0+dfsg-3 | 1.2.0+dfsg-3 |
| libimobiledevice | libimobiledevice | >= 0 < 1.2.0+dfsg-3 | 1.2.0+dfsg-3 |
| libimobiledevice | libimobiledevice | >= 0 < 1.2.0+dfsg-3 | 1.2.0+dfsg-3 |
| libimobiledevice | libusbmuxd | <= 1.0.10 | — |
| libimobiledevice | libusbmuxd | >= 0 < 1.0.10-3 | 1.0.10-3 |
| libimobiledevice | libusbmuxd | >= 0 < 1.0.10-3 | 1.0.10-3 |
| libimobiledevice | libusbmuxd | >= 0 < 1.0.10-3 | 1.0.10-3 |
| libimobiledevice | libusbmuxd | >= 0 < 1.0.10-3 | 1.0.10-3 |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libusbmuxd vulnerability
vendor_ubuntu·2016-07-05
CVE-2016-5104 libusbmuxd vulnerability
Title: libusbmuxd vulnerability
Summary: libusbmuxd would allow unintended access to devices over the network.
It was discovered that libusbmuxd incorrectly handled socket permissions.
A remote attacker could use this issue to access services on iOS devices,
contrary to expectations.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
libimobiledevice vulnerability
vendor_ubuntu·2016-07-05
CVE-2016-5104 libimobiledevice vulnerability
Title: libimobiledevice vulnerability
Summary: libimobiledevice would allow unintended access to devices over the network.
It was discovered that libimobiledevice incorrectly handled socket
permissions. A remote attacker could use this issue to access services on
iOS devices, contrary to expectations.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2016-5104: libimobiledevice - The socket_create function in common/socket.c in libimobiledevice and libusbmuxd...
vendor_debian·2016·CVSS 5.3
CVE-2016-5104 [MEDIUM] CVE-2016-5104: libimobiledevice - The socket_create function in common/socket.c in libimobiledevice and libusbmuxd...
The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket.
Scope: local
bookworm: resolved (fixed in 1.2.0+dfsg-3)
bullseye: resolved (fixed in 1.2.0+dfsg-3)
forky: resolved (fixed in 1.2.0+dfsg-3)
sid: resolved (fixed in 1.2.0+dfsg-3)
trixie: resolved (fixed in 1.2.0+dfsg-3)
Red Hat
libimobiledevice: Sockets listening on INADDR_ANY
vendor_redhat·2015-12-29·CVSS 5.3
CVE-2016-5104 [MEDIUM] libimobiledevice: Sockets listening on INADDR_ANY
libimobiledevice: Sockets listening on INADDR_ANY
The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket.
Package: libimobiledevice (Red Hat Enterprise Linux 6) - Not affected
Package: usbmuxd (Red Hat Enterprise Linux 6) - Will not fix
Package: libimobiledevice (Red Hat Enterprise Linux 7) - Will not fix
Package: usbmuxd (Red Hat Enterprise Linux 7) - Will not fix
GHSA
GHSA-v8rh-c9vm-p8g7: The socket_create function in common/socket
ghsa_unreviewed·2022-05-14
CVE-2016-5104 [MEDIUM] CWE-284 GHSA-v8rh-c9vm-p8g7: The socket_create function in common/socket
The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket.
OSV
CVE-2016-5104: The socket_create function in common/socket
osv·2016-06-13·CVSS 5.3
CVE-2016-5104 [MEDIUM] CVE-2016-5104: The socket_create function in common/socket
The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-5104 libimobiledevice: Sockets listening on INADDR_ANY
bugzilla·2016-05-26·CVSS 5.3
CVE-2016-5104 [MEDIUM] CVE-2016-5104 libimobiledevice: Sockets listening on INADDR_ANY
CVE-2016-5104 libimobiledevice: Sockets listening on INADDR_ANY
It was found that libimobiledevice and libusbmuxd libraries accidentally bound a listening IPv4 TCP socket to INADDR_ANY instead of INADDR_LOOPBACK.
This socket is used to communicate with services on an iOS device. The impact is accidental exposure of the iOS device to attackers on the local network. The RHEL workstation itself is not exposed, nor is there an easy escalation for attackers to gain access to the host.
Upstream patches:
libusbmuxd: https://github.com/libimobiledevice/libusbmuxd/commit/4397b3376dc4e4cb1c991d0aed61ce6482614196
libimobiledevice: https://github.com/libimobiledevice/libimobiledevice/commit/df1f5c4d70d0c19ad40072f5246ca457e7f9849e
CVE request:
http://seclists.org/oss-sec/2016/q2/410
Discussio
Bugzilla
CVE-2016-5104 libimobiledevice: Sockets listening on INADDR_ANY [fedora-all]
bugzilla·2016-05-26·CVSS 5.3
CVE-2016-5104 [MEDIUM] CVE-2016-5104 libimobiledevice: Sockets listening on INADDR_ANY [fedora-all]
CVE-2016-5104 libimobiledevice: Sockets listening on INADDR_ANY [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of F
Bugzilla
CVE-2016-5104 libusbmuxd: libimobiledevice: Sockets listening on INADDR_ANY [fedora-all]
bugzilla·2016-05-26·CVSS 5.3
CVE-2016-5104 [MEDIUM] CVE-2016-5104 libusbmuxd: libimobiledevice: Sockets listening on INADDR_ANY [fedora-all]
CVE-2016-5104 libusbmuxd: libimobiledevice: Sockets listening on INADDR_ANY [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00042.htmlhttp://lists.opensuse.org/opensuse-updates/2016-06/msg00029.htmlhttp://www.openwall.com/lists/oss-security/2016/05/26/1http://www.openwall.com/lists/oss-security/2016/05/26/6http://www.ubuntu.com/usn/USN-3026-1http://www.ubuntu.com/usn/USN-3026-2https://bugzilla.redhat.com/show_bug.cgi?id=1339988https://github.com/libimobiledevice/libimobiledevice/commit/df1f5c4d70d0c19ad40072f5246ca457e7f9849ehttps://github.com/libimobiledevice/libusbmuxd/commit/4397b3376dc4e4cb1c991d0aed61ce6482614196https://lists.debian.org/debian-lts-announce/2020/02/msg00027.htmlhttps://lists.debian.org/debian-lts-announce/2020/02/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00042.htmlhttp://lists.opensuse.org/opensuse-updates/2016-06/msg00029.htmlhttp://www.openwall.com/lists/oss-security/2016/05/26/1http://www.openwall.com/lists/oss-security/2016/05/26/6http://www.ubuntu.com/usn/USN-3026-1http://www.ubuntu.com/usn/USN-3026-2https://bugzilla.redhat.com/show_bug.cgi?id=1339988https://github.com/libimobiledevice/libimobiledevice/commit/df1f5c4d70d0c19ad40072f5246ca457e7f9849ehttps://github.com/libimobiledevice/libusbmuxd/commit/4397b3376dc4e4cb1c991d0aed61ce6482614196https://lists.debian.org/debian-lts-announce/2020/02/msg00027.htmlhttps://lists.debian.org/debian-lts-announce/2020/02/msg00028.html
2016-06-13
Published