Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
It was discovered that libimobiledevice incorrectly handled socket permissions. A remote attacker could use this issue to access services on iOS devices, contrary to expectations. . Package : libimobiledevice Version : 1.1.6+dfsg-3.1+deb8u1 CVE ID : CVE-2016-5104 Debian Bug : 825553 It was discovered that libimobiledevice incorrectly handled socket permissions. A remote attacker could use this issue to access services on iOS devices, contrary to expectations. For Debian 8 "Jessie", this problem has been fixed in version 1.1.6+dfsg-3.1+deb8u1. We recommend that you upgrade your libimobiledevice packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . An important security patch for libimobiledevice resolves socket access problems and potential remote exploitation vulnerabilities in Debian 8.. libimobiledevice update, Debian security patch, remote access security, socket permissions fix. . Severity: Critical. LinuxSecurity.com Team
The package libimobiledevice before version 1.2.0-4 is vulnerable to access restriction bypass. . Arch Linux Security Advisory ASA-201701-34 ========================================= Severity: Medium Date : 2017-01-27 CVE-ID : CVE-2016-5104 Package : libimobiledevice Type : access restriction bypass Remote : Yes Link : https://security.archlinux.org/AVG-8 Summary ====== The package libimobiledevice before version 1.2.0-4 is vulnerable to access restriction bypass. Resolution ========= Upgrade to 1.2.0-4. # pacman -Syu "libimobiledevice> =1.2.0-4" The problem has been fixed upstream but no release is available yet. Workaround ========= None. Description ========== The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers on the local network to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket. Impact ===== A remote attacker on the local network is able to bypass access restrictions and communicate with services on connected iOS devices. References ========= https://www.openwall.com/lists/oss-security/2016/05/26/6 https://security.archlinux.org/CVE-2016-5104 . Debian Security Notice reveals critical vulnerability in the libimobiledevice toolkit prior to version 1.2.0-5.. libimobiledevice Access Bypass, Arch Linux Advisory, Network Security Issue. . Severity: Medium. LinuxSecurity.com Team
libimobiledevice would allow unintended access to devices over the network.. =========================================================================Ubuntu Security Notice USN-3026-1 July 05, 2016 libimobiledevice vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS - Ubuntu 15.10 - Ubuntu 14.04 LTS Summary: libimobiledevice would allow unintended access to devices over the network. Software Description: - libimobiledevice: Library for communicating with iPhone and iPod Touch devices Details: It was discovered that libimobiledevice incorrectly handled socket permissions. A remote attacker could use this issue to access services on iOS devices, contrary to expectations. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: libimobiledevice6 1.2.0+dfsg-3~ubuntu0.2 Ubuntu 15.10: libimobiledevice4 1.1.6+dfsg-3.1ubuntu0.1 Ubuntu 14.04 LTS: libimobiledevice4 1.1.5+git20140313.bafe6a9e-0ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3026-1 CVE-2016-5104 Package Information: https://launchpad.net/ubuntu/+source/libimobiledevice/1.2.0+dfsg-3~ubuntu0.2 https://launchpad.net/ubuntu/+source/libimobiledevice/1.1.6+dfsg-3.1ubuntu0.1 https://launchpad.net/ubuntu/+source/libimobiledevice/1.1.5+git20140313.bafe6a9e-0ubuntu1.1 . Debian Security Advisory DSA-4982-1 points out a vulnerability in libimobiledevice, which could allow unauthorized network connections to devices.. libimobiledevice vulnerability,Ubuntu network access,remote access issues. . Severity: Critical. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.. SUSE Security Update: Security update for libimobiledevice, usbmuxd ______________________________________________________________________________ Announcement ID: SUSE-SU-2016:1639-1 Rating: important References: #982014 Cross-References: CVE-2016-5104 Affected Products: SUSE Linux Enterprise Workstation Extension 12-SP1 SUSE Linux Enterprise Workstation Extension 12 SUSE Linux Enterprise Software Development Kit 12-SP1 SUSE Linux Enterprise Software Development Kit 12 SUSE Linux Enterprise Server 12-SP1 SUSE Linux Enterprise Server 12 SUSE Linux Enterprise Desktop 12-SP1 SUSE Linux Enterprise Desktop 12 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: libimobiledevice, usbmuxd were updated to fix one security issue. This security issue was fixed: - CVE-2016-5104: Sockets listening on INADDR_ANY instead of only locally (982014). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP1: zypper in -t patch SUSE-SLE-WE-12-SP1-2016-973=1 - SUSE Linux Enterprise Workstation Extension 12: zypper in -t patch SUSE-SLE-WE-12-2016-973=1 - SUSE Linux Enterprise Software Development Kit 12-SP1: zypper in -t patch SUSE-SLE-SDK-12-SP1-2016-973=1 - SUSE Linux Enterprise Software Development Kit 12: zypper in -t patch SUSE-SLE-SDK-12-2016-973=1 - SUSE Linux Enterprise Server 12-SP1: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2016-973=1 - SUSE LinuxEnterprise Server 12: zypper in -t patch SUSE-SLE-SERVER-12-2016-973=1 - SUSE Linux Enterprise Desktop 12-SP1: zypper in -t patch SUSE-SLE-DESKTOP-12-SP1-2016-973=1 - SUSE Linux Enterprise Desktop 12: zypper in -t patch SUSE-SLE-DESKTOP-12-2016-973=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Workstation Extension 12-SP1 (x86_64): libimobiledevice-debugsource-1.1.5-6.1 libimobiledevice-tools-1.1.5-6.1 libimobiledevice-tools-debuginfo-1.1.5-6.1 - SUSE Linux Enterprise Workstation Extension 12 (x86_64): libimobiledevice-debugsource-1.1.5-6.1 libimobiledevice-tools-1.1.5-6.1 libimobiledevice-tools-debuginfo-1.1.5-6.1 - SUSE Linux Enterprise Software Development Kit 12-SP1 (ppc64le s390x x86_64): libimobiledevice-debugsource-1.1.5-6.1 libimobiledevice-devel-1.1.5-6.1 libusbmuxd-devel-1.0.8-12.1 usbmuxd-debuginfo-1.0.8-12.1 usbmuxd-debugsource-1.0.8-12.1 - SUSE Linux Enterprise Software Development Kit 12 (ppc64le s390x x86_64): libimobiledevice-debugsource-1.1.5-6.1 libimobiledevice-devel-1.1.5-6.1 libusbmuxd-devel-1.0.8-12.1 usbmuxd-debuginfo-1.0.8-12.1 usbmuxd-debugsource-1.0.8-12.1 - SUSE Linux Enterprise Server 12-SP1 (ppc64le s390x x86_64): libimobiledevice-debugsource-1.1.5-6.1 libimobiledevice4-1.1.5-6.1 libimobiledevice4-debuginfo-1.1.5-6.1 libusbmuxd2-1.0.8-12.1 libusbmuxd2-debuginfo-1.0.8-12.1 usbmuxd-1.0.8-12.1 usbmuxd-debuginfo-1.0.8-12.1 usbmuxd-debugsource-1.0.8-12.1 - SUSE Linux Enterprise Server 12 (ppc64le s390x x86_64): libimobiledevice-debugsource-1.1.5-6.1 libimobiledevice4-1.1.5-6.1 libimobiledevice4-debuginfo-1.1.5-6.1 libusbmuxd2-1.0.8-12.1 libusbmuxd2-debuginfo-1.0.8-12.1 usbmuxd-1.0.8-12.1 usbmuxd-debuginfo-1.0.8-12.1 usbmuxd-debugsource-1.0.8-12.1 - SUSE Linux Enterprise Desktop 12-SP1(x86_64): libimobiledevice-debugsource-1.1.5-6.1 libimobiledevice-tools-1.1.5-6.1 libimobiledevice-tools-debuginfo-1.1.5-6.1 libimobiledevice4-1.1.5-6.1 libimobiledevice4-debuginfo-1.1.5-6.1 libusbmuxd2-1.0.8-12.1 libusbmuxd2-debuginfo-1.0.8-12.1 usbmuxd-1.0.8-12.1 usbmuxd-debuginfo-1.0.8-12.1 usbmuxd-debugsource-1.0.8-12.1 - SUSE Linux Enterprise Desktop 12 (x86_64): libimobiledevice-debugsource-1.1.5-6.1 libimobiledevice-tools-1.1.5-6.1 libimobiledevice-tools-debuginfo-1.1.5-6.1 libimobiledevice4-1.1.5-6.1 libimobiledevice4-debuginfo-1.1.5-6.1 libusbmuxd2-1.0.8-12.1 libusbmuxd2-debuginfo-1.0.8-12.1 usbmuxd-1.0.8-12.1 usbmuxd-debuginfo-1.0.8-12.1 usbmuxd-debugsource-1.0.8-12.1 References: https://www.suse.com/security/cve/CVE-2016-5104.html https://bugzilla.suse.com/982014 . SUSE Security Update addressing vulnerabilities in libimobiledevice and usbmuxd resolves a critical security concern impacting various distributions.. SUSE Linux Enterprise, Security Update, libimobiledevice, usbmuxd. . Severity: Important. LinuxSecurity.com Team
libimobiledevice could be made to overwrite files as the administrator, or access device keys.. =========================================================================Ubuntu Security Notice USN-1927-1 August 14, 2013 libimobiledevice vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 13.04 - Ubuntu 12.10 Summary: libimobiledevice could be made to overwrite files as the administrator, or access device keys. Software Description: - libimobiledevice: Library for communicating with iPhone and iPod Touch devices Details: Paul Collins discovered that libimobiledevice incorrectly handled temporary files. A local attacker could possibly use this issue to overwrite arbitrary files and access device keys. In the default Ubuntu installation, this issue should be mitigated by the Yama link restrictions. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 13.04: libimobiledevice3 1.1.4-1ubuntu6.2 Ubuntu 12.10: libimobiledevice3 1.1.4-1ubuntu3.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1927-1 CVE-2013-2142 Package Information: https://launchpad.net/ubuntu/+source/libimobiledevice/1.1.4-1ubuntu6.2 https://launchpad.net/ubuntu/+source/libimobiledevice/1.1.4-1ubuntu3.2 . A serious alert about libimobiledevice highlights vulnerabilities that may allow unauthorized file overwrites and sensitive key exposure. Update your software now to mitigate risks. libimobiledevice, Ubuntu update, local attack, file access, security notice. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.