ELA-1599-1 usbmuxd security update

path traversal vulnerability

2025-12-22
Packageusbmuxd
Version1.1.0-2+deb9u1 (stretch), 1.1.1~git20181007.f838cf6-1+deb10u1 (buster)
Related CVEs CVE-2025-66004


It was discovered that usbmuxd, USB multiplexor daemon for iPhone and iPod Touch devices, incorrectly handled certain paths received with the SavePairRecord command. A local attacker could possibly use this issue to delete and write files named *.plist in arbitrary locations.



For Debian 10 buster, these problems have been fixed in version 1.1.1~git20181007.f838cf6-1+deb10u1.

For Debian 9 stretch, these problems have been fixed in version 1.1.0-2+deb9u1.

We recommend that you upgrade your usbmuxd packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.