{"id":"CVE-2013-2142","details":"userpref.c in libimobiledevice 1.1.4, when $HOME and $XDG_CONFIG_HOME are not set, allows local users to overwrite arbitrary files via a symlink attack on (1) HostCertificate.pem, (2) HostPrivateKey.pem, (3) libimobiledevicerc, (4) RootCertificate.pem, or (5) RootPrivateKey.pem in /tmp/root/.config/libimobiledevice/.","modified":"2026-04-16T06:19:51.908882782Z","published":"2014-01-19T18:02:56Z","related":["openSUSE-SU-2024:10459-1"],"references":[{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-1927-1"},{"type":"EVIDENCE","url":"https://bugs.launchpad.net/ubuntu/%2Bsource/libimobiledevice/%2Bbug/1164263"},{"type":"WEB","url":"http://libiphone.lighthouseapp.com/projects/27916-libiphone/tickets/331-insecure-tmp-directory-use"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2013/06/04/11"}],"schema_version":"1.7.5"}