Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-7982

Опубликовано: 20 апр. 2017
Источник: debian

Описание

Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted plist file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libplistfixed1.12+git+1+e37ca00-0.3package
libplistno-dsawheezypackage

Примечания

  • Fixed by: https://github.com/libimobiledevice/libplist/commit/fdebf8b319b9280cd0e9b4382f2c7cbf26ef9325

  • https://github.com/libimobiledevice/libplist/issues/103

  • The issue seems covered in prior versions of upstream dccd9290745345896e3a4a73154576a599fd8b7b

  • which is CVE-2017-6440.

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 9 лет назад

Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted plist file.

CVSS3: 3.3
redhat
почти 9 лет назад

Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted plist file.

CVSS3: 5.5
nvd
почти 9 лет назад

Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted plist file.

CVSS3: 5.5
github
больше 3 лет назад

Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted plist file.

suse-cvrf
больше 8 лет назад

Security update for libplist