CVE-2016-5104

The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
VendorProductVersion
libimobiledevicelibimobiledevice
𝑥
≤ 1.2.0
libimobiledevicelibusbmuxd
𝑥
≤ 1.0.10
canonicalubuntu_linux
14.04
canonicalubuntu_linux
15.10
canonicalubuntu_linux
16.04
opensuseleap
42.1
opensuseopensuse
13.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libimobiledevice
bookworm
1.3.0-6
fixed
bullseye
1.3.0-6
fixed
wheezy
not-affected
sid
1.3.0+git20240701-2
fixed
trixie
1.3.0+git20240701-2
fixed
libusbmuxd
bookworm
2.0.2-3
fixed
bullseye
2.0.2-3
fixed
wheezy
not-affected
sid
2.1.0-1
fixed
trixie
2.1.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libimobiledevice
zesty
Fixed 1.2.0+dfsg-3~ubuntu1
released
yakkety
Fixed 1.2.0+dfsg-3~ubuntu1
released
xenial
Fixed 1.2.0+dfsg-3~ubuntu0.2
released
wily
Fixed 1.1.6+dfsg-3.1ubuntu0.1
released
trusty
Fixed 1.1.5+git20140313.bafe6a9e-0ubuntu1.1
released
precise
not-affected
libusbmuxd
zesty
not-affected
yakkety
not-affected
xenial
Fixed 1.0.10-2ubuntu0.1
released
wily
Fixed 1.0.9-1ubuntu0.1
released
trusty
dne
precise
dne