CVE-2016-5104

MEDIUM

Libimobiledevice < 1.2.0 - Improper Access Control

Title source: rule

Description

The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket.

Scores

CVSS v3 5.3
EPSS 0.0175
EPSS Percentile 82.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Classification

CWE
CWE-284
Status draft

Affected Products (7)

libimobiledevice/libimobiledevice < 1.2.0
libimobiledevice/libusbmuxd < 1.0.10
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
opensuse/leap
opensuse/opensuse

Timeline

Published Jun 13, 2016
Tracked Since Feb 18, 2026