libplist

Link package | bugs open | bugs closed | Wiki | GitHub | web search
Description Library to handle Apple Property List files
Version 2.4.0-1 [extra]

Resolved

Group Affected Fixed Severity Status Ticket
AVG-413 1.12-1 2.0.0-1 Medium Fixed
AVG-215 1.12-6 2.0.0-1 High Fixed
Issue Group Severity Remote Type Description
CVE-2017-7982 AVG-413 Medium No Denial of service
Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause a denial of...
CVE-2017-6440 AVG-215 Medium No Denial of service
The parse_data_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory allocation error) via a...
CVE-2017-6439 AVG-215 Medium No Denial of service
Heap-based buffer overflow in the parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service...
CVE-2017-6438 AVG-215 High No Arbitrary command execution
Heap-based buffer overflow in the parse_unicode_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service...
CVE-2017-6437 AVG-215 Medium No Denial of service
The base64encode function in base64.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds read) via a crafted...
CVE-2017-6436 AVG-215 Medium No Denial of service
The parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory allocation error) via a...
CVE-2017-6435 AVG-215 Medium No Denial of service
The parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory corruption) via a...
CVE-2017-5836 AVG-215 High Yes Denial of service
The plist_free_data function in plist.c in libplist allows attackers to cause a denial of service (crash) via vectors involving an integer node that is...
CVE-2017-5835 AVG-215 High Yes Denial of service
libplist allows attackers to cause a denial of service (large memory allocation and crash) via vectors involving an offset size of zero.
CVE-2017-5834 AVG-215 High No Denial of service
The parse_dict_node function in bplist.c in libplist allows attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted file.
CVE-2017-5545 AVG-215 Medium No Denial of service
The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a...
CVE-2017-5209 AVG-215 High No Information disclosure
The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or...

Advisories

Date Advisory Group Severity Type
16 May 2017 ASA-201705-18 AVG-215 High multiple issues