CVE-2016-5104

NameCVE-2016-5104
DescriptionThe socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-2121-1, DLA-2122-1
Debian Bugs825553, 825554

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libimobiledevice (PTS)buster1.2.1~git20181030.92c5462-2+deb10u1fixed
bookworm, bullseye1.3.0-6fixed
sid, trixie1.3.0-7.1fixed
libusbmuxd (PTS)buster1.1.0~git20181007.07a493a-1fixed
bookworm, bullseye2.0.2-3fixed
sid, trixie2.0.2-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libimobiledevicesourcewheezy(not affected)
libimobiledevicesourcejessie1.1.6+dfsg-3.1+deb8u1DLA-2121-1
libimobiledevicesource(unstable)1.2.0+dfsg-3825553
libusbmuxdsourcejessie1.0.9-1+deb8u1DLA-2122-1
libusbmuxdsource(unstable)1.0.10-3825554

Notes

[wheezy] - libimobiledevice <not-affected> (Vulnerable code not present)
https://github.com/libimobiledevice/libimobiledevice/commit/df1f5c4d70d0c19ad40072f5246ca457e7f9849e
https://github.com/libimobiledevice/libusbmuxd/commit/4397b3376dc4e4cb1c991d0aed61ce6482614196

Search for package or bug name: Reporting problems