Friday, March 29, 2013

CVE-2013-0979


Lockdown
存在于iPhone3GS、iPod Touch4、iPad2之后的设备
影响:本地用户可改变任意文件权限
说明:从备份恢复时,可以通过改变文件路径中的一个符号链接,修复这个文件的权限

Lockdown
Available for:  iPhone 3GS and later,
iPod touch (4th generation) and later, iPad 2 and later
Impact:  A local user may be able to change permissions on arbitrary
files
Description:  When restoring from backup, lockdownd changed
permissions on certain files even if the path to the file included a
symbolic link. This issue was addressed by not changing permissions
on any file with a symlink in its path.
CVE-ID
CVE-2013-0979 : evad3rs

No comments:

Post a Comment