First published: Sun Jan 19 2014(Updated: )
userpref.c in libimobiledevice 1.1.4, when $HOME and $XDG_CONFIG_HOME are not set, allows local users to overwrite arbitrary files via a symlink attack on (1) HostCertificate.pem, (2) HostPrivateKey.pem, (3) libimobiledevicerc, (4) RootCertificate.pem, or (5) RootPrivateKey.pem in /tmp/root/.config/libimobiledevice/.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
libimobiledevice and libplist | =1.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2142 has a moderate severity as it allows local users to perform a symlink attack leading to file overwrites.
To fix CVE-2013-2142, ensure that the application is updated to a version that mitigates the symlink attack, or set $HOME and $XDG_CONFIG_HOME environment variables appropriately.
Users of libimobiledevice version 1.1.4 are affected by CVE-2013-2142 if their environment variables are not set.
The impact of CVE-2013-2142 is the potential for local users to overwrite critical configuration files, leading to unauthorized access or system compromise.
CVE-2013-2142 affects systems running libimobiledevice 1.1.4, which may include multiple operating systems that utilize this library.