Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-6438

Опубликовано: 15 мар. 2017
Источник: debian

Описание

Heap-based buffer overflow in the parse_unicode_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds write) and possibly code execution via a crafted plist file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libplistfixed1.12+git+1+e37ca00-0.2package
libplistno-dsajessiepackage
libplistnot-affectedwheezypackage

Примечания

  • https://github.com/libimobiledevice/libplist/issues/98

  • Fixed by: https://github.com/libimobiledevice/libplist/commit/dccd9290745345896e3a4a73154576a599fd8b7b

Связанные уязвимости

CVSS3: 7.3
ubuntu
почти 9 лет назад

Heap-based buffer overflow in the parse_unicode_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds write) and possibly code execution via a crafted plist file.

CVSS3: 3.3
redhat
почти 9 лет назад

Heap-based buffer overflow in the parse_unicode_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds write) and possibly code execution via a crafted plist file.

CVSS3: 7.3
nvd
почти 9 лет назад

Heap-based buffer overflow in the parse_unicode_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds write) and possibly code execution via a crafted plist file.

CVSS3: 7.3
github
больше 3 лет назад

Heap-based buffer overflow in the parse_unicode_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds write) and possibly code execution via a crafted plist file.

suse-cvrf
больше 8 лет назад

Security update for libplist