Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-2142

Опубликовано: 19 янв. 2014
Источник: nvd
CVSS2: 3.3
EPSS Низкий

Описание

userpref.c in libimobiledevice 1.1.4, when $HOME and $XDG_CONFIG_HOME are not set, allows local users to overwrite arbitrary files via a symlink attack on (1) HostCertificate.pem, (2) HostPrivateKey.pem, (3) libimobiledevicerc, (4) RootCertificate.pem, or (5) RootPrivateKey.pem in /tmp/root/.config/libimobiledevice/.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:libimobiledevice:libimobiledevice:1.1.4:*:*:*:*:*:*:*

EPSS

Процентиль: 5%
0.00022
Низкий

3.3 Low

CVSS2

Дефекты

CWE-59

Связанные уязвимости

ubuntu
около 12 лет назад

userpref.c in libimobiledevice 1.1.4, when $HOME and $XDG_CONFIG_HOME are not set, allows local users to overwrite arbitrary files via a symlink attack on (1) HostCertificate.pem, (2) HostPrivateKey.pem, (3) libimobiledevicerc, (4) RootCertificate.pem, or (5) RootPrivateKey.pem in /tmp/root/.config/libimobiledevice/.

redhat
больше 12 лет назад

userpref.c in libimobiledevice 1.1.4, when $HOME and $XDG_CONFIG_HOME are not set, allows local users to overwrite arbitrary files via a symlink attack on (1) HostCertificate.pem, (2) HostPrivateKey.pem, (3) libimobiledevicerc, (4) RootCertificate.pem, or (5) RootPrivateKey.pem in /tmp/root/.config/libimobiledevice/.

debian
около 12 лет назад

userpref.c in libimobiledevice 1.1.4, when $HOME and $XDG_CONFIG_HOME ...

github
больше 3 лет назад

userpref.c in libimobiledevice 1.1.4, when $HOME and $XDG_CONFIG_HOME are not set, allows local users to overwrite arbitrary files via a symlink attack on (1) HostCertificate.pem, (2) HostPrivateKey.pem, (3) libimobiledevicerc, (4) RootCertificate.pem, or (5) RootPrivateKey.pem in /tmp/root/.config/libimobiledevice/.

EPSS

Процентиль: 5%
0.00022
Низкий

3.3 Low

CVSS2

Дефекты

CWE-59