{"id":"CVE-2016-5104","details":"The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket.","modified":"2026-07-08T12:41:35.927776Z","published":"2016-06-13T14:59:08.290Z","related":["SUSE-SU-2016:1639-1","openSUSE-SU-2024:10373-1","openSUSE-SU-2024:10459-1"],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*"],"extracted_events":[{"introduced":"14.04"},{"last_affected":"14.04"},{"introduced":"15.10"},{"last_affected":"15.10"},{"introduced":"16.04"},{"last_affected":"16.04"}],"source":"CPE_STRING","vendor_product":"canonical:ubuntu_linux"},{"cpes":["cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"42.1"},{"last_affected":"42.1"}],"source":"CPE_STRING","vendor_product":"opensuse:leap"},{"cpes":["cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"13.2"},{"last_affected":"13.2"}],"source":"CPE_STRING","vendor_product":"opensuse:opensuse"}]},"references":[{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00042.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-updates/2016-06/msg00029.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2016/05/26/1"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2016/05/26/6"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2020/02/msg00027.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2020/02/msg00028.html"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-3026-1"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-3026-2"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1339988"},{"type":"FIX","url":"https://github.com/libimobiledevice/libimobiledevice/commit/df1f5c4d70d0c19ad40072f5246ca457e7f9849e"},{"type":"FIX","url":"https://github.com/libimobiledevice/libusbmuxd/commit/4397b3376dc4e4cb1c991d0aed61ce6482614196"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libimobiledevice/libimobiledevice","events":[{"introduced":"0"},{"last_affected":"a7568f456d10f1aff61534e3216201a857865247"},{"fixed":"df1f5c4d70d0c19ad40072f5246ca457e7f9849e"}],"database_specific":{"cpe":"cpe:2.3:a:libimobiledevice:libimobiledevice:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.2.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["1.2.0","1.1.7","1.1.6","1.1.5","1.1.4","1.1.3","1.1.2","1.1.1","1.1.0","1.0.0","0.9.7","0.9.6","0.9.4","0.9.1","0.9.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-5104.json","vanir_signatures_modified":"2026-07-08T12:41:35Z","vanir_signatures":[{"id":"CVE-2016-5104-0b34d219","signature_type":"Function","signature_version":"v1","source":"https://github.com/libimobiledevice/libimobiledevice/commit/df1f5c4d70d0c19ad40072f5246ca457e7f9849e","target":{"file":"common/socket.c","function":"socket_accept"},"deprecated":false,"digest":{"function_hash":"223227762218740381546236436231339953424","length":381}},{"digest":{"line_hashes":["275643151166302349810472022840261964543","105265269734791624689809604482401513936","173739618565877628694836254607531225877","259035628592790214567187436227432747798","317135530018679773566625740995765424989","136895671501312672497746562487745663119","138589304419312984673149195511634798580","70553262767019701130621632544616767841"],"threshold":0.9},"id":"CVE-2016-5104-5b6c18ac","signature_type":"Line","signature_version":"v1","source":"https://github.com/libimobiledevice/libimobiledevice/commit/df1f5c4d70d0c19ad40072f5246ca457e7f9849e","target":{"file":"common/socket.c"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"187151911723170418934941065368462817934","length":970},"id":"CVE-2016-5104-f90f0101","signature_type":"Function","signature_version":"v1","source":"https://github.com/libimobiledevice/libimobiledevice/commit/df1f5c4d70d0c19ad40072f5246ca457e7f9849e","target":{"function":"socket_create","file":"common/socket.c"}}]}},{"ranges":[{"type":"GIT","repo":"https://github.com/libimobiledevice/libusbmuxd","events":[{"introduced":"0"},{"last_affected":"fe871d7a2fb67170ecc27c5b88d84585d0de6a89"},{"fixed":"4397b3376dc4e4cb1c991d0aed61ce6482614196"}],"database_specific":{"cpe":"cpe:2.3:a:libimobiledevice:libusbmuxd:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.0.10"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["1.0.10","1.0.9"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-5104.json","vanir_signatures_modified":"2026-07-08T12:41:35Z","vanir_signatures":[{"id":"CVE-2016-5104-1a758fee","signature_type":"Function","signature_version":"v1","source":"https://github.com/libimobiledevice/libusbmuxd/commit/4397b3376dc4e4cb1c991d0aed61ce6482614196","target":{"file":"common/socket.c","function":"socket_create"},"deprecated":false,"digest":{"length":1163,"function_hash":"140393950915423373818402424906255544444"}},{"target":{"file":"common/socket.c","function":"socket_accept"},"deprecated":false,"digest":{"function_hash":"223227762218740381546236436231339953424","length":381},"id":"CVE-2016-5104-6ff2ddc7","signature_type":"Function","signature_version":"v1","source":"https://github.com/libimobiledevice/libusbmuxd/commit/4397b3376dc4e4cb1c991d0aed61ce6482614196"},{"digest":{"line_hashes":["90987712388113087796451535517335473532","105265269734791624689809604482401513936","173739618565877628694836254607531225877","259035628592790214567187436227432747798","317135530018679773566625740995765424989","136895671501312672497746562487745663119","138589304419312984673149195511634798580","70553262767019701130621632544616767841"],"threshold":0.9},"id":"CVE-2016-5104-afd83fa4","signature_type":"Line","signature_version":"v1","source":"https://github.com/libimobiledevice/libusbmuxd/commit/4397b3376dc4e4cb1c991d0aed61ce6482614196","target":{"file":"common/socket.c"},"deprecated":false}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}