CVE-2013-0979: Low severity apple iPhone OS vulnerability
lockdownd in Lockdown in Apple iOS before 6.1.3 does not properly consider file types during the permission-setting step of a backup restoration, which allows local users to change the permissions of arbitrary files via a backup that contains a pathname with a symlink.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0979?
CVE-2013-0979 is classified as a medium severity vulnerability due to potential unauthorized access to file permissions.
How do I fix CVE-2013-0979?
To fix CVE-2013-0979, update your iOS device to version 6.1.3 or later as it contains the necessary security patch.
What systems are affected by CVE-2013-0979?
CVE-2013-0979 affects Apple iOS versions prior to 6.1.3, including early versions like 1.0.0 up to 6.1.2.
Can CVE-2013-0979 be exploited locally?
Yes, CVE-2013-0979 can be exploited by local users through the manipulation of backup files containing symlinks.
What risks are associated with CVE-2013-0979?
The risks include allowing local users to change file permissions, which could lead to unauthorized access or data compromise.