CVE-2016-5104

NameCVE-2016-5104
DescriptionThe socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium (attack range: remote)
Debian Bugs825553, 825554

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libimobiledevice (PTS)jessie1.1.6+dfsg-3.1vulnerable
stretch1.2.0+dfsg-3.1fixed
buster, bullseye, sid1.2.1~git20181030.92c5462-1fixed
libusbmuxd (PTS)jessie1.0.9-1vulnerable
stretch1.0.10-3fixed
buster, bullseye, sid1.1.0~git20181007.07a493a-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libimobiledevicesource(unstable)1.2.0+dfsg-3medium825553
libimobiledevicesourcewheezy(not affected)
libusbmuxdsource(unstable)1.0.10-3medium825554

Notes

[jessie] - libimobiledevice <no-dsa> (Minor issue)
[wheezy] - libimobiledevice <not-affected> (Vulnerable code not present)
https://github.com/libimobiledevice/libimobiledevice/commit/df1f5c4d70d0c19ad40072f5246ca457e7f9849e
[jessie] - libusbmuxd <no-dsa> (Minor issue)
https://github.com/libimobiledevice/libusbmuxd/commit/4397b3376dc4e4cb1c991d0aed61ce6482614196

Search for package or bug name: Reporting problems