CVE-2016-5104

EUVD-2016-6055
The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
Affected Products (NVD)
VendorProductVersion
libimobiledevicelibimobiledevice
𝑥
≤ 1.2.0
libimobiledevicelibusbmuxd
𝑥
≤ 1.0.10
canonicalubuntu_linux
14.04
canonicalubuntu_linux
15.10
canonicalubuntu_linux
16.04
opensuseleap
42.1
opensuseopensuse
13.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libimobiledevice
bookworm
1.3.0-6
fixed
bullseye
1.3.0-6
fixed
sid
1.3.0+git20240701-2
fixed
trixie
1.3.0+git20240701-2
fixed
wheezy
not-affected
libusbmuxd
bookworm
2.0.2-3
fixed
bullseye
2.0.2-3
fixed
sid
2.1.0-1
fixed
trixie
2.1.0-1
fixed
wheezy
not-affected
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libimobiledevice
precise
not-affected
trusty
Fixed 1.1.5+git20140313.bafe6a9e-0ubuntu1.1
released
wily
Fixed 1.1.6+dfsg-3.1ubuntu0.1
released
xenial
Fixed 1.2.0+dfsg-3~ubuntu0.2
released
yakkety
Fixed 1.2.0+dfsg-3~ubuntu1
released
zesty
Fixed 1.2.0+dfsg-3~ubuntu1
released
libusbmuxd
precise
dne
trusty
dne
wily
Fixed 1.0.9-1ubuntu0.1
released
xenial
Fixed 1.0.10-2ubuntu0.1
released
yakkety
not-affected
zesty
not-affected