LWN.net Logo

libimobiledevice: file overwrite and device key access

Package(s):libimobiledevice CVE #(s):CVE-2013-2142
Created:August 15, 2013 Updated:August 21, 2013
Description:

From the Ubuntu advisory:

Paul Collins discovered that libimobiledevice incorrectly handled temporary files. A local attacker could possibly use this issue to overwrite arbitrary files and access device keys. In the default Ubuntu installation, this issue should be mitigated by the Yama link restrictions.

Alerts:
Ubuntu USN-1927-1 2013-08-14
Mageia MGASA-2013-0251 2013-08-17

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds