CVE-2013-5133: High severity apple iPhone OS vulnerability
Published Mar 14, 2014
·Updated
Backup in Apple iOS before 7.1 does not properly restrict symlinks, which allows remote attackers to overwrite files during a restore operation via crafted backup data.
Affected Software
7 affected components
apple iPhone OS<=7.0.6
apple iPhone OS=7.0
apple iPhone OS=7.0.1
apple iPhone OS=7.0.2
apple iPhone OS=7.0.3
apple iPhone OS=7.0.4
apple iPhone OS=7.0.5
Event History
Mar 14, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:55 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-5133?
CVE-2013-5133 is classified as a medium severity vulnerability due to its potential for remote exploitation.
2
How do I fix CVE-2013-5133?
To fix CVE-2013-5133, upgrade your Apple iOS device to version 7.1 or later.
3
Who is affected by CVE-2013-5133?
CVE-2013-5133 affects devices running Apple iOS versions prior to 7.1, including 7.0 to 7.0.6.
4
What type of attack does CVE-2013-5133 allow?
CVE-2013-5133 allows remote attackers to overwrite files during a restore operation by using crafted backup data.
5
Can CVE-2013-5133 be exploited without user interaction?
Yes, CVE-2013-5133 can be exploited remotely without requiring user interaction.