userpref.c in libimobiledevice 1.1.4, when $HOME and $XDG_CONFIG_HOME are not set, allows local users to overwrite arbitrary files via a symlink attack on (1) HostCertificate.pem, (2) HostPrivateKey.pem, (3) libimobiledevicerc, (4) RootCertificate.pem, or (5) RootPrivateKey.pem in /tmp/root/.config/libimobiledevice/.
CVSS Details
- CVSS 3.1 Base Score: 4.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libimobiledevice | Jul 30, 2024 | Jan 19, 2014 |
| Suse | — | Upgrade libimobiledevice6Upgrade imobiledevice-toolsUpgrade libimobiledevice-devel | Aug 9, 2024 | Jan 19, 2014 |
| Ubuntu | — | Upgrade libimobiledevice3 | Nov 8, 2024 | Jan 19, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub